Cookie types
What Are Secure Cookies?
A Secure cookie is a cookie with the Secure attribute enabled. This tells the browser to send it over HTTPS, where communication is encrypted, rather than over an ordinary HTTP connection. A limited exception applies to localhost development.
Consider a cookie that identifies a signed-in customer. If it travels over an unencrypted connection, someone intercepting that traffic could potentially obtain it. The Secure attribute helps prevent that exposure.
However, the name can be misleading: “Secure” describes one protection, not complete security.
What Secure does | What Secure does not do |
|---|---|
Restricts cookie transmission to HTTPS, apart from the localhost exception. | Encrypt the cookie’s stored contents. |
Helps protect the cookie against interception during transmission. | Prevent JavaScript from reading the cookie. |
Adds a browser-enforced transport restriction. | Guarantee that the cookie’s purpose or use is privacy-compliant. |
To restrict JavaScript access, use HttpOnly cookies. Developers commonly combine both attributes with suitable SameSite settings, as described in MDN’s secure cookie configuration guidance.
Türkçe
English