Cookie types
What Are SameSite Cookies?
SameSite is a cookie attribute that controls when a browser sends a cookie with requests coming from another site. It helps websites limit situations in which an outside page can cause a visitor’s cookies to accompany a request.
The three settings behave differently:
Setting | Behaviour | Practical example |
|---|---|---|
| Sends the cookie only with same-site requests. | Following a link from another site does not include the cookie in the initial request. |
| Also allows cross-site top-level navigation using safe methods, such as GET. | Opening a normal link can include the cookie, while a cross-site POST form submission generally cannot. |
| Allows same-site and cross-site use, subject to other browser restrictions. Requires | An embedded service may need this setting to receive a cookie inside another website. |
Here, “same-site” is broader than “same hostname”: HTTPS subdomains of the same registrable domain can be same-site.
SameSite helps reduce certain cross-site attacks, but it does not grant consent or override third-party cookie blocking. Developers should set it explicitly rather than assume identical browser defaults. MDN’s SameSite documentation provides the detailed rules.
Türkçe
English