Cross-Domain Cookie Behavior
Understanding how cookies work across different domains is essential for multi-domain applications and tracking scenarios.
Same-Site vs Cross-Site
Same-Site
Two domains are considered same-site if they share the same eTLD+1 (effective Top-Level Domain + 1).
Examples:
example.comandshop.example.com→ Same-site (bothexample.com)www.example.comandapi.example.com→ Same-siteexample.co.ukandshop.example.co.uk→ Same-site
Cookie Behavior:
- Same-site cookies are sent with requests
- Less restricted by browser policies
- Can share cookies via Domain attribute
Cross-Site
Two domains are cross-site if they have different eTLD+1.
Examples:
example.comandotherdomain.com→ Cross-siteshop.example.comandtracker.adnetwork.com→ Cross-siteexample.comandsubdomain.otherdomain.com→ Cross-site
Cookie Behavior:
- Cross-site cookies are heavily restricted
- Requires
SameSite=None; Secure - Subject to browser blocking policies
Cookie Sharing Strategies
Strategy 1: Parent Domain Cookie
Setup:
- Cookie set with
Domain=example.com - Accessible by
example.comand all subdomains
Example:
Set-Cookie: session=abc; Domain=example.com; Path=/
Accessible By:
- ✅
example.com - ✅
www.example.com - ✅
shop.example.com - ✅
api.example.com - ❌
otherdomain.com
Use Case: Shared authentication across subdomains
Strategy 2: Exact Domain Cookie
Setup:
- Cookie set without Domain attribute or with exact domain
- Only accessible by that exact domain
Example:
Set-Cookie: preference=dark; Path=/
# or explicitly:
Set-Cookie: preference=dark; Domain=shop.example.com; Path=/
Accessible By:
- ✅
shop.example.com(only) - ❌
example.com - ❌
www.example.com
Use Case: Subdomain-specific configuration
Strategy 3: Cross-Site Cookie (SameSite=None)
Setup:
- Cookie with
SameSite=None; Secure - Can be sent with cross-site requests
Example:
Set-Cookie: tracking=xyz; Domain=tracker.com; SameSite=None; Secure; Path=/
Accessible By:
- Can be sent to
tracker.comfrom any site - Requires HTTPS
- Subject to browser blocking
Use Case: Cross-site tracking (declining due to browser restrictions)
Testing Cross-Domain Scenarios
Test 1: Subdomain Sharing
Procedure:
- Visit
https://cookie-playground.pun7o.click - Set cookie:
Domain=cookie-playground.pun7o.click - Visit
https://site-a.cookie-playground.pun7o.click - Verify cookie is accessible
Expected Result: Cookie accessible by both domains (same-site)
Sequence Diagram:
(cookie-playground.pun7o.click) participant SubA as Subdomain A
(site-a.cookie-playground.pun7o.click) participant Browser User->>Parent: Visit cookie-playground.pun7o.click Parent->>Browser: Set-Cookie: shared=value
Domain=cookie-playground.pun7o.click
Path=/ Browser->>Browser: Store cookie (Domain=cookie-playground.pun7o.click) User->>SubA: Navigate to site-a.cookie-playground.pun7o.click Browser->>Browser: Check cookies (Domain=cookie-playground.pun7o.click matches subdomain) Browser->>SubA: GET /page HTTP/1.1
Cookie: shared=value Note over Browser,SubA: Cookie accessible because
subdomain can access parent domain cookies SubA->>Browser: HTTP 200 OK
Test 2: Cross-Site Cookie
Procedure:
- Visit
https://site-a.cookie-playground.pun7o.click - Load pixel from
https://cookie-playground.pun7o.click/pixel - If pixel sets cookie with
SameSite=None; Secure, check if it's stored
Expected Result: Depends on browser and SameSite policy
Sequence Diagram - SameSite=None:
(site-a.cookie-playground.pun7o.click) participant Parent as Parent Domain
(cookie-playground.pun7o.click) participant Browser User->>SubA: Visit site-a.cookie-playground.pun7o.click SubA->>Browser: HTML with pixel: cookie-playground.pun7o.click/pixel Browser->>Parent: GET /pixel HTTP/1.1
Cookie: (parent cookies if any) Note over Browser,Parent: Cross-site request
(different subdomain) Parent->>Browser: Set-Cookie: tracking=xyz
Domain=cookie-playground.pun7o.click
SameSite=None
Secure Browser->>Browser: Store cookie (if browser allows SameSite=None) Parent->>Browser: HTTP 200 OK
1x1 GIF Note over Browser: Cookie stored if SameSite=None allowed
(may be blocked by browser privacy features)
Test 3: Parent Domain Access
Procedure:
- Visit
https://site-a.cookie-playground.pun7o.click - Set cookie:
Domain=site-a.cookie-playground.pun7o.click - Visit
https://cookie-playground.pun7o.click - Try to access cookie
Expected Result: Cookie NOT accessible by parent (one-way relationship)
Sequence Diagram:
(site-a.cookie-playground.pun7o.click) participant Parent as Parent Domain
(cookie-playground.pun7o.click) participant Browser User->>SubA: Visit site-a.cookie-playground.pun7o.click SubA->>Browser: Set-Cookie: subdomain_only=abc
Domain=site-a.cookie-playground.pun7o.click
Path=/ Browser->>Browser: Store cookie (Domain=site-a.cookie-playground.pun7o.click) User->>Parent: Navigate to cookie-playground.pun7o.click Browser->>Browser: Check cookies for cookie-playground.pun7o.click Note over Browser: Cookie with Domain=site-a.cookie-playground.pun7o.click
does NOT match cookie-playground.pun7o.click Browser->>Parent: GET /page HTTP/1.1
Cookie: (subdomain_only NOT sent) Note over Browser,Parent: Parent cannot access subdomain cookie
(one-way relationship) Parent->>Browser: HTTP 200 OK
Common Patterns
Pattern 1: Multi-Tenant Application
Scenario: Each subdomain is a tenant
Solution:
// Shared authentication cookie
document.cookie = "session=abc; Domain=app.example.com; Path=/; Secure";
// Tenant-specific cookie
document.cookie = "tenant=tenant123; Domain=a.app.example.com; Path=/; Secure";
Result:
- Session cookie accessible by all tenants
- Tenant cookie only accessible by that tenant
Pattern 2: CDN Cookie Sharing
Scenario: CDN serves content from subdomain
Solution:
// Set cookie on main domain
document.cookie = "preference=dark; Domain=example.com; Path=/; Secure";
Result:
- Cookie accessible by main domain
- Cookie accessible by CDN subdomain (
cdn.example.com)
Pattern 3: Third-Party Integration
Scenario: Embed third-party widget that needs to track user
Solution (becoming less viable):
// On tracker.com
document.cookie = "user_id=123; Domain=tracker.com; SameSite=None; Secure; Path=/";
Result:
- Cookie accessible by tracker.com
- Can be sent with requests from other sites
- Warning: Many browsers block this
Browser Differences
Chrome
- Phasing out third-party cookies (2024+)
- SameSite=Lax default for new cookies
- Cookies must be set via HTTPS for cross-site
Firefox
- Enhanced Tracking Protection blocks third-party cookies
- SameSite=Lax default
- Users can configure tracking protection levels
Safari
- Intelligent Tracking Prevention (ITP) blocks third-party cookies
- 24-hour expiration for cross-site cookies
- First-party cookie isolation
Edge
- Following Chrome's approach
- SameSite=Lax default
- Third-party cookie blocking planned
Security Considerations
Cookie Hijacking Prevention
Secure Flag:
- Always use
Secureflag for cross-site cookies - Ensures cookies only sent over HTTPS
HttpOnly Flag:
- Prevents JavaScript access
- Reduces XSS attack surface
SameSite Attribute:
Strict: Most secure, prevents CSRFLax: Balanced security and functionalityNone: Least secure, requiresSecure
Domain Spoofing
Prevention:
- Be explicit with Domain attribute
- Don't set Domain to top-level domains
- Validate cookie domains server-side
Troubleshooting Cross-Domain Issues
Cookie Not Accessible Across Subdomains
Problem: Cookie set on shop.example.com not accessible by www.example.com
Solution:
- Set
Domain=example.com(parent domain) - Ensures cookie accessible by all subdomains
Cookie Blocked in Cross-Site Request
Problem: Third-party cookie not being sent
Possible Causes:
- Missing
SameSite=None - Missing
Secureflag - Browser blocking third-party cookies
- Not using HTTPS
Solution:
- Add
SameSite=None; Secureto cookie - Ensure HTTPS is used
- Consider alternatives to third-party cookies
Cookie Accessible When It Shouldn't Be
Problem: Cookie set for subdomain accessible by parent
Cause: Domain attribute set to parent domain
Solution:
- Set Domain to exact subdomain or omit Domain attribute
- Parent cannot access subdomain-specific cookies
Best Practices
- Use Parent Domain for Shared Cookies:
Domain=example.comfor cross-subdomain sharing - Be Explicit: Always specify Domain attribute when needed
- Use Secure Flag: Always use
Securefor production - Consider SameSite: Choose appropriate SameSite value
- Test in Multiple Browsers: Behavior can vary
- Monitor Browser Changes: Third-party cookie restrictions evolving
Related Topics
- First-Party vs Third-Party - Cookie classification
- Parent-Subdomain Cookies - Specific subdomain scenarios
- Cookie Attributes - Domain and SameSite attributes
- Browser Behaviors - Browser-specific differences
Next Steps
- Test cross-domain scenarios in the playground
- Learn about Parent-Subdomain Cookies for detailed subdomain behavior
- Explore HTTP Headers to see how cookies are sent