Secure cookie

Secure cookie
ConceptCryptography and Computer Security

An HTTP cookie restricted to secure channels by the Secure attribute.

1.25Uncommon
No. 06359Kosmora

Uncommon

Secure cookie

  • Cryptography and Computer Security

A secure cookie is an HTTP cookie with the Secure attribute set. A user agent, typically a web browser, sends it only when an HTTP request uses a secure channel, typically HTTPS. The attribute protects cookie confidentiality but not integrity, since an active network attacker can overwrite Secure cookies through an insecure channel. Other cookie protections include HttpOnly, which restricts script access, and SameSite, which limits sending based on request origin.

The picture on this card was made with AI. It is an illustration, not a real photo of the subject.

Purpose
Limits a cookie's scope to secure channels.
Transmission rule
Sent only over a secure channel, typically HTTPS.
Integrity limitation
An active network attacker can overwrite Secure cookies from an insecure channel.
Sources and credits

Sources and credits

Article
Secure cookie (English Wikipedia)
Wikidata
Q28402843
Text
Card text is adapted from the English Wikipedia article by an automated summary. Wikipedia content is available under CC BY-SA 4.0; see the article history for its contributors. CC BY-SA 4.0 · Article history and contributors
Illustration
AI-generated illustration. Not a photograph or documentary image. (model: gpt-image-2.5-flare)
Popularity
27 median daily views (Wikimedia Pageviews API (all-access, user agent))

Kosmora is not affiliated with or endorsed by the Wikimedia Foundation.