Cross-Domain Cookie Behavior

Understanding how cookies work across different domains is essential for multi-domain applications and tracking scenarios.

Same-Site vs Cross-Site

Same-Site

Two domains are considered same-site if they share the same eTLD+1 (effective Top-Level Domain + 1).

Examples:

Cookie Behavior:

Cross-Site

Two domains are cross-site if they have different eTLD+1.

Examples:

Cookie Behavior:

Setup:

Example:

Set-Cookie: session=abc; Domain=example.com; Path=/

Accessible By:

Use Case: Shared authentication across subdomains

Setup:

Example:

Set-Cookie: preference=dark; Path=/
# or explicitly:
Set-Cookie: preference=dark; Domain=shop.example.com; Path=/

Accessible By:

Use Case: Subdomain-specific configuration

Setup:

Example:

Set-Cookie: tracking=xyz; Domain=tracker.com; SameSite=None; Secure; Path=/

Accessible By:

Use Case: Cross-site tracking (declining due to browser restrictions)

Testing Cross-Domain Scenarios

Test 1: Subdomain Sharing

Procedure:

  1. Visit https://cookie-playground.pun7o.click
  2. Set cookie: Domain=cookie-playground.pun7o.click
  3. Visit https://site-a.cookie-playground.pun7o.click
  4. Verify cookie is accessible

Expected Result: Cookie accessible by both domains (same-site)

Sequence Diagram:

sequenceDiagram participant User participant Parent as Parent Domain
(cookie-playground.pun7o.click) participant SubA as Subdomain A
(site-a.cookie-playground.pun7o.click) participant Browser User->>Parent: Visit cookie-playground.pun7o.click Parent->>Browser: Set-Cookie: shared=value
Domain=cookie-playground.pun7o.click
Path=/ Browser->>Browser: Store cookie (Domain=cookie-playground.pun7o.click) User->>SubA: Navigate to site-a.cookie-playground.pun7o.click Browser->>Browser: Check cookies (Domain=cookie-playground.pun7o.click matches subdomain) Browser->>SubA: GET /page HTTP/1.1
Cookie: shared=value Note over Browser,SubA: Cookie accessible because
subdomain can access parent domain cookies SubA->>Browser: HTTP 200 OK

Procedure:

  1. Visit https://site-a.cookie-playground.pun7o.click
  2. Load pixel from https://cookie-playground.pun7o.click/pixel
  3. If pixel sets cookie with SameSite=None; Secure, check if it's stored

Expected Result: Depends on browser and SameSite policy

Sequence Diagram - SameSite=None:

sequenceDiagram participant User participant SubA as Subdomain A
(site-a.cookie-playground.pun7o.click) participant Parent as Parent Domain
(cookie-playground.pun7o.click) participant Browser User->>SubA: Visit site-a.cookie-playground.pun7o.click SubA->>Browser: HTML with pixel: cookie-playground.pun7o.click/pixel Browser->>Parent: GET /pixel HTTP/1.1
Cookie: (parent cookies if any) Note over Browser,Parent: Cross-site request
(different subdomain) Parent->>Browser: Set-Cookie: tracking=xyz
Domain=cookie-playground.pun7o.click
SameSite=None
Secure Browser->>Browser: Store cookie (if browser allows SameSite=None) Parent->>Browser: HTTP 200 OK
1x1 GIF Note over Browser: Cookie stored if SameSite=None allowed
(may be blocked by browser privacy features)

Test 3: Parent Domain Access

Procedure:

  1. Visit https://site-a.cookie-playground.pun7o.click
  2. Set cookie: Domain=site-a.cookie-playground.pun7o.click
  3. Visit https://cookie-playground.pun7o.click
  4. Try to access cookie

Expected Result: Cookie NOT accessible by parent (one-way relationship)

Sequence Diagram:

sequenceDiagram participant User participant SubA as Subdomain A
(site-a.cookie-playground.pun7o.click) participant Parent as Parent Domain
(cookie-playground.pun7o.click) participant Browser User->>SubA: Visit site-a.cookie-playground.pun7o.click SubA->>Browser: Set-Cookie: subdomain_only=abc
Domain=site-a.cookie-playground.pun7o.click
Path=/ Browser->>Browser: Store cookie (Domain=site-a.cookie-playground.pun7o.click) User->>Parent: Navigate to cookie-playground.pun7o.click Browser->>Browser: Check cookies for cookie-playground.pun7o.click Note over Browser: Cookie with Domain=site-a.cookie-playground.pun7o.click
does NOT match cookie-playground.pun7o.click Browser->>Parent: GET /page HTTP/1.1
Cookie: (subdomain_only NOT sent) Note over Browser,Parent: Parent cannot access subdomain cookie
(one-way relationship) Parent->>Browser: HTTP 200 OK

Common Patterns

Pattern 1: Multi-Tenant Application

Scenario: Each subdomain is a tenant

Solution:

// Shared authentication cookie
document.cookie = "session=abc; Domain=app.example.com; Path=/; Secure";

// Tenant-specific cookie
document.cookie = "tenant=tenant123; Domain=a.app.example.com; Path=/; Secure";

Result:

Scenario: CDN serves content from subdomain

Solution:

// Set cookie on main domain
document.cookie = "preference=dark; Domain=example.com; Path=/; Secure";

Result:

Pattern 3: Third-Party Integration

Scenario: Embed third-party widget that needs to track user

Solution (becoming less viable):

// On tracker.com
document.cookie = "user_id=123; Domain=tracker.com; SameSite=None; Secure; Path=/";

Result:

Browser Differences

Chrome

Firefox

Safari

Edge

Security Considerations

Secure Flag:

HttpOnly Flag:

SameSite Attribute:

Domain Spoofing

Prevention:

Troubleshooting Cross-Domain Issues

Problem: Cookie set on shop.example.com not accessible by www.example.com

Solution:

Problem: Third-party cookie not being sent

Possible Causes:

  1. Missing SameSite=None
  2. Missing Secure flag
  3. Browser blocking third-party cookies
  4. Not using HTTPS

Solution:

Problem: Cookie set for subdomain accessible by parent

Cause: Domain attribute set to parent domain

Solution:

Best Practices

  1. Use Parent Domain for Shared Cookies: Domain=example.com for cross-subdomain sharing
  2. Be Explicit: Always specify Domain attribute when needed
  3. Use Secure Flag: Always use Secure for production
  4. Consider SameSite: Choose appropriate SameSite value
  5. Test in Multiple Browsers: Behavior can vary
  6. Monitor Browser Changes: Third-party cookie restrictions evolving

Next Steps