Skip to content

Set Cookie — Reference

Reference · Advanced · Server Connect

Send a cookie value to the browser through the server response.

Send a cookie value to the browser through the server response.

  • An open Server Connect action. Runtime differences below refer to the installed Node.js and PHP implementations.

Send a cookie value to the browser through the server response.

Setting Meaning
NameThe cookie name, such as preferred_language.
ValueThe value to write. Prefer a small string such as en for consistent behavior across server models.
DomainOptional cookie domain. Omit it for the response host rather than supplying an unrelated hostname.
PathThe request-path scope for the cookie. The inspector defaults to /. For example, / makes it eligible throughout the site; /account narrows its path scope.
ExpiresExpiration in days, not a date string. The inspector shows 30. Runtime omission differs: Node.js uses 30 days; PHP omits the Expires attribute. Zero is also different: Node.js treats it as a session cookie, while PHP creates an expiry at the current time. Use an explicit positive lifetime when portability matters and inspect the saved options and Set-Cookie response.
SecureRestricts cookie transmission to secure requests when enabled. The UI represents a boolean flag; test it over HTTPS.
Http OnlyPrevents client-side JavaScript from reading the cookie when enabled. Use server-side inspection for such a cookie; App Connect Cookie Manager cannot read it.
Same SiteControls the SameSite attribute: Default, None, Lax or Strict. It governs cross-site cookie sending, not authorization. Verify the browser’s handling of the selected policy; None commonly also requires Secure.

In a test action, set preferred_language = en, Path / and an explicit positive Expires value. Call the action and inspect Set-Cookie plus the browser’s stored cookie. Call a second endpoint under the same path and check that the browser sends the cookie back.

Cookie presence does not prove identity or permission. Keep authentication in the Security Provider. The installed PHP writer checks whether secure/httpOnly options are present, not their boolean value, so omit false flags in hand-authored PHP action configuration and verify generated headers.

Use the Server Connect guides when you need the surrounding project, data-loading or form procedure.

You can configure Set Cookie deliberately and verify the result and failure behavior described in this reference.