← All headersResponse header

What is a Set-Cookie header?

Instructs the client to store a cookie, to be sent back on future requests to the same site.

Set-Cookie is how a website establishes state with a visitor's browser - sessions, authentication, preferences, all of it typically flows through this one header, along with its attributes like Secure, HttpOnly, and SameSite that control how safely that cookie behaves. A subtly wrong SameSite or Secure setting can break login flows for a subset of visitors (often only on certain browsers) without ever producing a server error, which makes it a genuinely tricky class of bug to catch without monitoring that maintains real cookie state across checks.

Common use case

A login endpoint sets a session cookie via Set-Cookie with HttpOnly and Secure flags, so the session token is inaccessible to JavaScript (blocking XSS-based theft) and only ever sent over HTTPS.

Example

Set-Cookie: session_id=a1b2c3d4; Secure; HttpOnly; SameSite=Lax; Max-Age=3600

History

Cookies originated at Netscape in 1994; Set-Cookie was formalised in RFC 2109 (1997) and modernised with the SameSite attribute in RFC 6265bis (2016 onwards).

Did you know?

The SameSite=Lax default that browsers now apply automatically, introduced around 2020, single-handedly closed off a huge class of cross-site request forgery attacks that had existed since cookies were invented.