HTTP Headers - Cookie and Set-Cookie
Understanding HTTP headers is essential for cookie management. This guide covers the Cookie and Set-Cookie headers in detail.
Set-Cookie Header
The Set-Cookie header is sent by the server to instruct the browser to store a cookie.
Basic Format
Set-Cookie: <name>=<value>; <attribute1>=<value1>; <attribute2>=<value2>
Complete Example
Set-Cookie: session=abc123xyz; Domain=example.com; Path=/; Secure; HttpOnly; SameSite=Strict; Max-Age=3600
Breakdown:
session=abc123xyz: Cookie name and valueDomain=example.com: Domain attributePath=/: Path attributeSecure: Secure flagHttpOnly: HttpOnly flagSameSite=Strict: SameSite attributeMax-Age=3600: Expiration (1 hour)
Set-Cookie Header Components
1. Name-Value Pair
Format: <name>=<value>
Rules:
- Name: Alphanumeric,
-,_(no spaces) - Value: Can contain most characters, but should be URL-encoded if special
- Separated by
=sign
Examples:
Set-Cookie: user=john
Set-Cookie: session_id=abc123
Set-Cookie: preference=dark%20mode (URL-encoded value)
2. Domain Attribute
Format: Domain=<domain>
Examples:
Set-Cookie: session=abc; Domain=example.com
Set-Cookie: session=abc; Domain=.example.com (leading dot optional)
Behavior:
- Specifies which domains can access the cookie
- If omitted, cookie only for exact domain
- Dot prefix (
.example.com) is optional and equivalent
3. Path Attribute
Format: Path=<path>
Examples:
Set-Cookie: cart=items; Path=/
Set-Cookie: admin=settings; Path=/admin
Behavior:
- Cookie sent only with requests matching the path
- Default is
/(root path) - Subpaths are included (e.g.,
/adminincludes/admin/users)
4. Expires Attribute
Format: Expires=<date>
Date Format: RFC 1123 format
Expires=Wed, 21 Oct 2025 07:28:00 GMT
Behavior:
- Sets absolute expiration date
- Cookie deleted after expiration
- Dates in the past delete the cookie immediately
5. Max-Age Attribute
Format: Max-Age=<seconds>
Examples:
Set-Cookie: session=abc; Max-Age=3600 (1 hour)
Set-Cookie: session=abc; Max-Age=86400 (1 day)
Behavior:
- Sets relative expiration time
- Takes precedence over
Expiresif both present - Negative value or 0 deletes cookie immediately
6. Secure Flag
Format: Secure (no value)
Examples:
Set-Cookie: session=abc; Secure
Set-Cookie: session=abc; Domain=example.com; Secure
Behavior:
- Cookie only sent over HTTPS connections
- Required for
SameSite=None - Recommended for all production cookies
7. HttpOnly Flag
Format: HttpOnly (no value)
Examples:
Set-Cookie: session=abc; HttpOnly
Set-Cookie: session=abc; Secure; HttpOnly
Behavior:
- Cookie not accessible via
document.cookiein JavaScript - Only sent in HTTP requests
- Protects against XSS attacks
8. SameSite Attribute
Format: SameSite=<value>
Values: Strict, Lax, None
Examples:
Set-Cookie: session=abc; SameSite=Strict
Set-Cookie: tracking=xyz; SameSite=None; Secure
Behavior:
- Controls when cookie sent in cross-site requests
NonerequiresSecureflag- Modern browsers default to
Laxif omitted
Cookie Header
The Cookie header is sent by the browser to the server with each request.
Format
Cookie: <name1>=<value1>; <name2>=<value2>; <name3>=<value3>
Example
Cookie: session=abc123xyz; preference=dark; cart=item1,item2
Characteristics:
- Contains only name-value pairs
- No attributes (attributes only in Set-Cookie)
- Multiple cookies separated by semicolon and space
- URL-encoded if needed
Multiple Cookies
Request:
GET /page HTTP/1.1
Host: example.com
Cookie: session=abc123; user_pref=dark; cart=item1
Browser Behavior:
- Automatically includes all matching cookies
- Matches based on Domain and Path attributes
- Sorted (order not guaranteed)
HTTP Request/Response Flow
Complete Example
1. Client Request (no cookies initially):
GET /login HTTP/1.1
Host: example.com
2. Server Response (sets cookie):
HTTP/1.1 200 OK
Set-Cookie: session=abc123; Domain=example.com; Path=/; Secure; HttpOnly; SameSite=Strict; Max-Age=3600
Content-Type: text/html
3. Subsequent Client Request (includes cookie):
GET /dashboard HTTP/1.1
Host: example.com
Cookie: session=abc123
4. Server Response (can update cookie):
HTTP/1.1 200 OK
Set-Cookie: session=abc123; Domain=example.com; Path=/; Secure; HttpOnly; SameSite=Strict; Max-Age=3600
Content-Type: text/html
Sequence Diagram - Cookie Flow:
(example.com) participant CookieStore as Cookie Storage User->>Browser: Navigate to example.com/login Browser->>Server: GET /login HTTP/1.1
Host: example.com
Cookie: (none) Server->>Browser: HTTP 200 OK
Set-Cookie: session=abc123
Domain=example.com
Path=/
Secure
HttpOnly
SameSite=Strict
Max-Age=3600
Content-Type: text/html Browser->>CookieStore: Store cookie
{name: session, value: abc123, domain: example.com, path: /, secure: true, httpOnly: true, sameSite: Strict, maxAge: 3600} CookieStore-->>Browser: Cookie stored Browser->>User: Display login page User->>Browser: Submit login form Browser->>CookieStore: Retrieve cookies for example.com, path=/ CookieStore-->>Browser: session=abc123 Browser->>Server: POST /login HTTP/1.1
Host: example.com
Cookie: session=abc123 Server->>Browser: HTTP 302 Found
Location: /dashboard
Set-Cookie: session=abc123
Domain=example.com
Path=/
Secure
HttpOnly
SameSite=Strict
Max-Age=3600 Browser->>Server: GET /dashboard HTTP/1.1
Host: example.com
Cookie: session=abc123 Server->>Browser: HTTP 200 OK
Content-Type: text/html Browser->>User: Display dashboard
Status Codes and Cookies
200 OK
- Cookies can be set with successful responses
- Most common status for Set-Cookie
301/302 Redirect
- Cookies can be set on redirect responses
- Browser follows redirect and includes cookies if applicable
- Redirect target may receive cookies in request
400 Bad Request
- Can set cookies even on error responses
- Useful for error tracking or session maintenance
403 Forbidden / 401 Unauthorized
- Can set cookies for authentication attempts
- Used for session management during auth flows
Header Order
Multiple Set-Cookie Headers
Multiple cookies set in one response:
HTTP/1.1 200 OK
Set-Cookie: session=abc123; Domain=example.com; Path=/; Secure
Set-Cookie: preference=dark; Domain=example.com; Path=/; Secure
Set-Cookie: cart=items; Domain=example.com; Path=/shop; Secure
Content-Type: text/html
Note: Each cookie requires separate Set-Cookie header
URL Encoding
Special Characters
Cookies may contain special characters that need encoding:
Example:
Set-Cookie: user=John%20Doe; Domain=example.com
Decoded: user=John Doe
Common Encoding:
- Space:
%20 - Semicolon:
%3B - Equals:
%3D - Comma:
%2C
Cookie Size Limits
Browser Limits
- Per Cookie: ~4096 bytes (name + value + attributes)
- Per Domain: Varies (typically 50-150 cookies)
- Total Size: Varies by browser
Best Practices
- Keep cookie values small
- Use session IDs instead of large data
- Store data server-side, use cookie as reference
Header Inspection in Playground
Viewing Set-Cookie Headers
In Browser DevTools:
- Open DevTools (F12)
- Go to Network tab
- Click on a request
- View "Response Headers"
- Look for
Set-Cookieheader
In Playground Inspector:
- HTTP inspector shows Set-Cookie headers
- Displays full cookie string with all attributes
- Shows status code and response details
Viewing Cookie Headers
In Browser DevTools:
- Open DevTools (F12)
- Go to Network tab
- Click on a request
- View "Request Headers"
- Look for
Cookieheader
In Playground:
- HTTP inspector shows Cookie headers
- Displays all cookies sent with request
- Shows which cookies match Domain and Path
Common Patterns
Pattern 1: Session Management
Login Response:
Set-Cookie: session=abc123xyz; Domain=example.com; Path=/; Secure; HttpOnly; SameSite=Strict; Max-Age=86400
Subsequent Requests:
Cookie: session=abc123xyz
Pattern 2: Preference Storage
Setting Preference:
Set-Cookie: theme=dark; Domain=example.com; Path=/; Secure; SameSite=Lax; Max-Age=31536000
Reading Preference:
Cookie: theme=dark
Pattern 3: Tracking Pixel
Pixel Request (includes tracking cookies):
GET /pixel?id=123 HTTP/1.1
Host: tracker.com
Cookie: user_id=456; session=xyz
Referer: https://example.com/page
Pixel Response (can set new cookies):
HTTP/1.1 200 OK
Content-Type: image/gif
Set-Cookie: tracking=789; Domain=tracker.com; Path=/; Secure; SameSite=None; Max-Age=63072000
Troubleshooting
Cookie Not Being Set
Check:
- Set-Cookie header present in response?
- Domain attribute correct?
- Secure flag required for HTTPS?
- Browser console errors?
Cookie Not Being Sent
Check:
- Cookie domain matches request domain?
- Cookie path matches request path?
- Cookie expired?
- SameSite policy blocking?
- Browser blocking third-party cookies?
Multiple Cookies Not Working
Check:
- Each cookie has separate Set-Cookie header?
- Cookie names unique?
- Size limits not exceeded?
- Browser cookie limits not reached?
Security Best Practices
- Always Use Secure:
Secureflag for HTTPS sites - Use HttpOnly: For sensitive cookies (sessions, tokens)
- Set Appropriate SameSite: Balance security and functionality
- Validate Server-Side: Don't trust cookie values
- URL Encode: Encode special characters in values
- Limit Cookie Scope: Use restrictive Domain and Path when possible
Related Topics
- Cookie Attributes - Detailed attribute explanations
- HTTP Inspection - How to inspect headers
- Browser Behaviors - Browser-specific header handling
Next Steps
- Use the playground's HTTP inspector to view headers
- Learn about HTTP Inspection for detailed inspection guide
- Review Cookie Attributes for attribute details