Cookie types

Knowledge Base | Cookie types | What Are SameSite Cookies?

What Are SameSite Cookies?

SameSite is a cookie attribute that controls when a browser sends a cookie with requests coming from another site. It helps websites limit situations in which an outside page can cause a visitor’s cookies to accompany a request.

The three settings behave differently:

Setting

Behaviour

Practical example

Strict

Sends the cookie only with same-site requests.

Following a link from another site does not include the cookie in the initial request.

Lax

Also allows cross-site top-level navigation using safe methods, such as GET.

Opening a normal link can include the cookie, while a cross-site POST form submission generally cannot.

None

Allows same-site and cross-site use, subject to other browser restrictions. Requires Secure.

An embedded service may need this setting to receive a cookie inside another website.

Here, “same-site” is broader than “same hostname”: HTTPS subdomains of the same registrable domain can be same-site.

SameSite helps reduce certain cross-site attacks, but it does not grant consent or override third-party cookie blocking. Developers should set it explicitly rather than assume identical browser defaults. MDN’s SameSite documentation provides the detailed rules.