Cookie types

Knowledge Base | Cookie types | What Is the Difference Between Host-Only and Domain Cookies?

What Is the Difference Between Host-Only and Domain Cookies?

The difference is the range of hosts to which the browser can send the cookie.

A host-only cookie is restricted to the exact host that sets it. A domain cookie can also be sent to subdomains within its declared scope. 

Example set by shop.example.com

Where the cookie can be sent

No Domain attribute

Only shop.example.com.

Domain=shop.example.com

shop.example.com and its subdomains, such as support.shop.example.com.

Domain=example.com

example.com and its subdomains, including shop.example.com and account.example.com.

Other restrictions, such as path and Secure settings, still apply. A website cannot set a domain cookie for an unrelated domain it does not control.

Host-only cookies provide a narrower scope. Domain cookies can support shared functionality across subdomains, but should be used only where that broader access is needed.

This distinction is separate from the difference between first-party and third-party cookies. Host-only versus domain describes scope; first-party versus third-party describes the cookie’s context relative to the site being visited.