Free tools Windows power users keep installed
One-click scans. No signup required.
Set the sameSite property on the cookie data passed to Puppeteer’s BrowserContext.setCookie(). Use 'Lax' for cookies that should accompany eligible top-level safe cross-site navigations but not ordinary cross-site fetches or embedded resources; use 'None' with secure: true when the cookie must be available in cross-site contexts. Puppeteer also accepts 'Strict' and 'Default'. Puppeteer’s CookieSameSite type documents those values.
Set SameSite in Puppeteer
Pass sameSite as part of the cookie object to the browser context that will make the request. The example below uses an HTTPS URL so that the cookie has an explicit scope:
await page.browserContext().setCookie({
name: 'session',
value: 'example',
url: 'https://example.test',
sameSite: 'Lax',
});
sameSite is optional in Puppeteer’s cookie data object. The context-level method is useful when pages in a particular context need the cookie. Browser.setCookie() is also available as a shortcut for setting cookies in the browser’s default context. See the BrowserContext.setCookie() reference and Browser.setCookie() reference.
For a cookie that must be sent in a cross-site context, set both attributes:
Recommended Free Tools
#1 Best Overall
await page.browserContext().setCookie({
name: 'session',
value: 'example',
url: 'https://example.test',
sameSite: 'None',
secure: true,
});
Choose the cookie’s URL or domain and path to match the application. SameSite controls cross-site sending; it does not replace cookie scope, expiry, or other attributes.
What each SameSite value permits
| Value | Cross-site behavior | When to choose it |
|---|---|---|
Strict |
Restricts the cookie to same-site requests. | Use when the cookie should not accompany cross-site requests. |
Lax |
Allows same-site requests and eligible cross-site top-level navigations using safe methods. It does not cover typical cross-site fetches, embedded resources, or unsafe methods. | Use when ordinary link-style navigation should work, but cross-site subrequests should not receive the cookie. |
None |
Allows same-site and cross-site requests, subject to the cookie’s Secure requirement and browser cookie policies. | Use only when the application genuinely needs cross-site inclusion; pair it with secure: true. |
Default |
Uses the browser’s default handling rather than an explicitly selected policy. | Use only if relying on browser defaults is intentional. |
These request rules are summarized in MDN’s Set-Cookie reference. “Cross-site” behavior depends on the context of the request: a top-level navigation is different from a fetch, iframe, or other embedded resource request.
Rank #2
Why a Puppeteer cookie may be missing cross-site
A cookie can be set successfully and still be excluded from a particular request. Check these causes in order:
- The request type does not qualify.
Laxcan cover eligible top-level safe navigations, but not typical cross-site fetches, embedded resources, or unsafe methods. For a real cross-site use case, trysameSite: 'None'withsecure: true. - The cookie was set in a different context. Set it on the browser context used by the page making the request, or use
Browser.setCookie()if the default context is intended. - The cookie scope does not match. Verify its URL or domain and path, along with expiry and other attributes. SameSite does not override those restrictions.
- The cookie relies on an omitted value. Chromium uses Lax as its default, but defaults can differ among browsers. Set the intended value explicitly when consistency matters. See MDN’s third-party cookie guidance.
- The browser blocks third-party cookies.
SameSite=Nonedoes not guarantee acceptance or transmission in every browser; separate third-party-cookie policies may still apply.
Security attributes are separate
SameSite can reduce some cross-site request forgery (CSRF) exposure, but it is not a complete CSRF defense. For session cookies, consider HttpOnly and Secure for their distinct purposes: HttpOnly prevents access through client-side scripts, while Secure restricts transmission to secure connections. Neither changes the site-boundary rules controlled by SameSite.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
Or skip the browser setup
If your goal is a website screenshot rather than testing cookie behavior in Puppeteer, ScreenshotNeo returns a screenshot or PDF from one GET request. Cookie banners are accepted and removed before capture, along with known newsletter popups and chat widgets; those cleanup steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000.
cURL example (replace the target URL as needed; see the ScreenshotNeo API documentation):
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Sign up for 1,000 free screenshots a month, with no card required.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




