Parent-Subdomain Cookie Behavior
Understanding how cookies work between parent domains and their subdomains is crucial for multi-domain architectures.
Domain Hierarchy
In our playground:
- Parent Domain:
cookie-playground.pun7o.click - Subdomain A:
site-a.cookie-playground.pun7o.click - Subdomain B:
site-b.cookie-playground.pun7o.click
Key Principles
1. Parent Domain Cookies
Setting: Cookie with Domain=cookie-playground.pun7o.click
Accessibility:
- ✅ Parent domain (
cookie-playground.pun7o.click) - ✅ Subdomain A (
site-a.cookie-playground.pun7o.click) - ✅ Subdomain B (
site-b.cookie-playground.pun7o.click)
Example:
// Set on parent domain
document.cookie = "shared_cookie=value; Domain=cookie-playground.pun7o.click; Path=/";
All three domains can read this cookie.
2. Subdomain-Specific Cookies
Setting: Cookie with Domain=site-a.cookie-playground.pun7o.click
Accessibility:
- ✅ Subdomain A (
site-a.cookie-playground.pun7o.click) - ❌ Parent domain (
cookie-playground.pun7o.click) - ❌ Subdomain B (
site-b.cookie-playground.pun7o.click)
Example:
// Set on subdomain A
document.cookie = "subdomain_a_cookie=value; Domain=site-a.cookie-playground.pun7o.click; Path=/";
Only subdomain A can read this cookie.
3. No Domain Attribute
Setting: Cookie without Domain attribute
Accessibility:
- ✅ Only the exact domain that set it
- ❌ Other domains, including parent and siblings
Example:
// Set on subdomain A without Domain attribute
document.cookie = "exact_domain_cookie=value; Path=/";
Only site-a.cookie-playground.pun7o.click can read this cookie.
Practical Scenarios
Scenario 1: Shared Session Across Subdomains
Goal: Maintain user session across parent and all subdomains
Solution: Set cookie with parent domain
document.cookie = "session_id=abc123; Domain=cookie-playground.pun7o.click; Path=/; Secure; HttpOnly";
Sequence Diagram:
(cookie-playground.pun7o.click) participant SubA as Subdomain A
(site-a.cookie-playground.pun7o.click) participant Browser User->>Parent: Visit cookie-playground.pun7o.click Parent->>Browser: Set-Cookie: session_id=abc123
Domain=cookie-playground.pun7o.click Browser->>Browser: Store cookie (Domain=cookie-playground.pun7o.click) User->>SubA: Navigate to site-a.cookie-playground.pun7o.click Browser->>SubA: GET /page HTTP/1.1
Cookie: session_id=abc123 Note over Browser,SubA: Cookie accessible because
Domain=cookie-playground.pun7o.click User->>Parent: Return to cookie-playground.pun7o.click Browser->>Parent: GET /page HTTP/1.1
Cookie: session_id=abc123 Note over Browser,Parent: Cookie accessible on parent domain
Scenario 2: Subdomain-Specific Configuration
Goal: Store configuration only accessible by specific subdomain
Solution: Set cookie with subdomain domain
document.cookie = "config=subdomain_a_only; Domain=site-a.cookie-playground.pun7o.click; Path=/";
Sequence Diagram:
(site-a.cookie-playground.pun7o.click) participant Parent as Parent Domain
(cookie-playground.pun7o.click) participant Browser User->>SubA: Visit site-a.cookie-playground.pun7o.click SubA->>Browser: Set-Cookie: config=a_only
Domain=site-a.cookie-playground.pun7o.click Browser->>Browser: Store cookie (Domain=site-a.cookie-playground.pun7o.click) User->>SubA: Request on site-a.cookie-playground.pun7o.click Browser->>SubA: GET /page HTTP/1.1
Cookie: config=a_only Note over Browser,SubA: Cookie accessible on subdomain A User->>Parent: Navigate to cookie-playground.pun7o.click Browser->>Parent: GET /page HTTP/1.1
Cookie: (no config cookie) Note over Browser,Parent: Cookie NOT accessible
Parent cannot access subdomain cookie
Scenario 3: Preventing Parent Access to Subdomain Data
Goal: Ensure parent domain cannot access subdomain-specific cookies
Solution: Always set subdomain-specific cookies with the subdomain as Domain
document.cookie = "private_data=secret; Domain=site-a.cookie-playground.pun7o.click; Path=/; Secure; HttpOnly";
Sequence Diagram:
(site-a.cookie-playground.pun7o.click) participant Parent as Parent Domain
(cookie-playground.pun7o.click) participant Browser User->>SubA: Visit site-a.cookie-playground.pun7o.click SubA->>Browser: Set-Cookie: private=secret
Domain=site-a.cookie-playground.pun7o.click Browser->>Browser: Store cookie with Domain=site-a.cookie-playground.pun7o.click User->>SubA: Request on site-a.cookie-playground.pun7o.click Browser->>SubA: GET /page HTTP/1.1
Cookie: private=secret Note over Browser,SubA: Subdomain can access its own cookie User->>Parent: Navigate to cookie-playground.pun7o.click Browser->>Parent: GET /page HTTP/1.1
Cookie: (private cookie NOT sent) Note over Browser,Parent: Parent cannot access subdomain cookie
(one-way relationship) User->>SubA: Return to site-a.cookie-playground.pun7o.click Browser->>SubA: GET /page HTTP/1.1
Cookie: private=secret Note over Browser,SubA: Cookie still accessible on subdomain
Testing in the Playground
- Visit Parent Domain:
https://cookie-playground.pun7o.click/parent-subdomain-test.html - Set Parent Domain Cookie: Use the test button to set a cookie with
Domain=cookie-playground.pun7o.click - Visit Subdomain A:
https://site-a.cookie-playground.pun7o.click/parent-subdomain-test.html - Verify Access: You should see the parent domain cookie
- Set Subdomain Cookie: Set a cookie with
Domain=site-a.cookie-playground.pun7o.click - Return to Parent: The parent cannot access the subdomain-specific cookie
Common Pitfalls
Pitfall 1: Assuming Bidirectional Access
❌ Wrong: "If subdomain can access parent cookies, parent can access subdomain cookies"
✅ Correct: Subdomains can access parent cookies, but NOT vice versa
Pitfall 2: Omitting Domain Attribute
❌ Wrong: Setting cookie without Domain and expecting subdomain access
✅ Correct: Explicitly set Domain attribute for cross-subdomain access
Pitfall 3: Wrong Domain Value
❌ Wrong: Domain=.cookie-playground.pun7o.click (leading dot not necessary)
✅ Correct: Domain=cookie-playground.pun7o.click
Real-World Applications
- Multi-Tenant Applications: Each subdomain is a tenant, with shared authentication cookies
- Content Delivery: CDN subdomains share parent domain cookies for authentication
- Analytics: Parent domain cookie tracks users across all subdomains
- Isolation: Subdomain-specific cookies ensure data separation
Related Topics
- Cookie Attributes - Understanding Domain attribute
- Cross-Domain Behavior - Broader cross-domain concepts
- HTTP Headers - How Set-Cookie header works
Next Steps
- Test in the playground: Parent-Subdomain Test Pages
- Learn about HTTP Headers to see the actual Set-Cookie format