1 min read 59 words Updated Sep 24, 2026 Created Sep 24, 2026
#APIs#JavaScript#webdev
  • Are automatically added to requests, regardless of origin

Cookie flags

SameSite

Controls whether cookies are sent with cross-site requests,

Options are:

  • Lax
  • Strict

HttpOnly

Prevents JS access, protecting against XSS attacks.

Yet, I believe they can be accessed by browser extensions.

Secure

Only sendings cookies over HTTPS, therefore via en encrypted connection.