Skip to content

How to set Secure, HttpOnly and SameSite on cookies

Security1 min readFixes 3 checks cookie-secure, cookie-httponly, cookie-samesite

Three cookie attributes stop cookies from leaking over HTTP, being read by scripts or being sent in cross-site requests.

Step by step, with screenshots: Cookie flags explained: Secure, HttpOnly and SameSite →

Check your own site

Runs these 3 checks and the other 184, free, in about 45 seconds.

What a passing site looks like

  • Secure flag on cookies: passeswarning · −2.5 ptseffort S
  • HttpOnly flag on cookies: passeswarning · −2 ptseffort S
  • SameSite attribute on cookies: passeswarning · −1.5 ptseffort S

Filed under Security. Copy is generated from the same catalogue that scores every report, so what you read here is what the report says.