Question

What does the SameSite cookie attribute do?

Vault Verified
Curated Intelligence
Definitive Source
Answer

SameSite controls whether a cookie is sent on requests originating from a different site. It exists primarily to mitigate cross-site request forgery, where a malicious page causes your browser to make an authenticated request to a site you are logged into, relying on the cookie being attached automatically.

There are three values.

Strict never sends the cookie on any cross-site request. It is the safest and has a noticeable side effect: following a link from another site to yours arrives without the cookie, so the user appears logged out until they navigate again. That is often unacceptable for a session cookie and fine for a sensitive one.

Lax sends the cookie on top-level navigations using safe methods, so following a link works, but withholds it on form posts, embedded images and background requests from other sites. This is the modern default in browsers when the attribute is absent, and it is a reasonable balance for session cookies.

None sends the cookie on all cross-site requests, restoring the old behaviour. Browsers require the secure flag alongside it, so it only works over HTTPS. This is needed for genuine cross-site use cases such as embedded widgets and some authentication flows.

The change to defaulting to Lax broke a number of integrations that relied on unspecified behaviour, which is why the attribute suddenly became widely discussed. If something worked previously and now fails only in a cross-site context, this is a strong candidate.

SameSite is a defence in depth measure rather than a complete solution. It should be combined with anti-forgery tokens for state-changing operations, since browser behaviour varies and older clients may not enforce it.

Related Questions