Cookie types

Knowledge Base | Cookie types | What Are Secure Cookies?

What Are Secure Cookies?

A Secure cookie is a cookie with the Secure attribute enabled. This tells the browser to send it over HTTPS, where communication is encrypted, rather than over an ordinary HTTP connection. A limited exception applies to localhost development.

Consider a cookie that identifies a signed-in customer. If it travels over an unencrypted connection, someone intercepting that traffic could potentially obtain it. The Secure attribute helps prevent that exposure.

However, the name can be misleading: “Secure” describes one protection, not complete security.

What Secure does

What Secure does not do

Restricts cookie transmission to HTTPS, apart from the localhost exception.

Encrypt the cookie’s stored contents.

Helps protect the cookie against interception during transmission.

Prevent JavaScript from reading the cookie.

Adds a browser-enforced transport restriction.

Guarantee that the cookie’s purpose or use is privacy-compliant.

To restrict JavaScript access, use HttpOnly cookies. Developers commonly combine both attributes with suitable SameSite settings, as described in MDN’s secure cookie configuration guidance.