Set Cookie — Reference
Send a cookie value to the browser through the server response.
Send a cookie value to the browser through the server response.
Before you begin
Section titled “Before you begin”- An open Server Connect action. Runtime differences below refer to the installed Node.js and PHP implementations.
Set Cookie
Section titled “Set Cookie”Send a cookie value to the browser through the server response.
Settings and execution
Section titled “Settings and execution”| Setting | Meaning |
|---|---|
| Name | The cookie name, such as preferred_language. |
| Value | The value to write. Prefer a small string such as en for consistent behavior across server models. |
| Domain | Optional cookie domain. Omit it for the response host rather than supplying an unrelated hostname. |
| Path | The request-path scope for the cookie. The inspector defaults to /. For example, / makes it eligible throughout the site; /account narrows its path scope. |
| Expires | Expiration in days, not a date string. The inspector shows 30. Runtime omission differs: Node.js uses 30 days; PHP omits the Expires attribute. Zero is also different: Node.js treats it as a session cookie, while PHP creates an expiry at the current time. Use an explicit positive lifetime when portability matters and inspect the saved options and Set-Cookie response. |
| Secure | Restricts cookie transmission to secure requests when enabled. The UI represents a boolean flag; test it over HTTPS. |
| Http Only | Prevents client-side JavaScript from reading the cookie when enabled. Use server-side inspection for such a cookie; App Connect Cookie Manager cannot read it. |
| Same Site | Controls the SameSite attribute: Default, None, Lax or Strict. It governs cross-site cookie sending, not authorization. Verify the browser’s handling of the selected policy; None commonly also requires Secure. |
Worked example
Section titled “Worked example”In a test action, set preferred_language = en, Path / and an explicit positive Expires value. Call the action and inspect Set-Cookie plus the browser’s stored cookie. Call a second endpoint under the same path and check that the browser sends the cookie back.
Check the behavior and limits
Section titled “Check the behavior and limits”Cookie presence does not prove identity or permission. Keep authentication in the Security Provider. The installed PHP writer checks whether secure/httpOnly options are present, not their boolean value, so omit false flags in hand-authored PHP action configuration and verify generated headers.
Continue with a task
Section titled “Continue with a task”Use the Server Connect guides when you need the surrounding project, data-loading or form procedure.
Check your result
Section titled “Check your result”You can configure Set Cookie deliberately and verify the result and failure behavior described in this reference.