Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk3 min

Puppeteer Cookie SameSite Settings Explained

Set SameSite on Puppeteer cookie data and choose the right value for same-site requests, cross-site navigation, or third-party contexts.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set the sameSite property on the cookie data passed to Puppeteer’s BrowserContext.setCookie(). Use 'Lax' for cookies that should accompany eligible top-level safe cross-site navigations but not ordinary cross-site fetches or embedded resources; use 'None' with secure: true when the cookie must be available in cross-site contexts. Puppeteer also accepts 'Strict' and 'Default'. Puppeteer’s CookieSameSite type documents those values.

Set SameSite in Puppeteer

Pass sameSite as part of the cookie object to the browser context that will make the request. The example below uses an HTTPS URL so that the cookie has an explicit scope:

await page.browserContext().setCookie({
  name: 'session',
  value: 'example',
  url: 'https://example.test',
  sameSite: 'Lax',
});

sameSite is optional in Puppeteer’s cookie data object. The context-level method is useful when pages in a particular context need the cookie. Browser.setCookie() is also available as a shortcut for setting cookies in the browser’s default context. See the BrowserContext.setCookie() reference and Browser.setCookie() reference.

For a cookie that must be sent in a cross-site context, set both attributes:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
await page.browserContext().setCookie({
  name: 'session',
  value: 'example',
  url: 'https://example.test',
  sameSite: 'None',
  secure: true,
});

Choose the cookie’s URL or domain and path to match the application. SameSite controls cross-site sending; it does not replace cookie scope, expiry, or other attributes.

What each SameSite value permits

Value Cross-site behavior When to choose it
Strict Restricts the cookie to same-site requests. Use when the cookie should not accompany cross-site requests.
Lax Allows same-site requests and eligible cross-site top-level navigations using safe methods. It does not cover typical cross-site fetches, embedded resources, or unsafe methods. Use when ordinary link-style navigation should work, but cross-site subrequests should not receive the cookie.
None Allows same-site and cross-site requests, subject to the cookie’s Secure requirement and browser cookie policies. Use only when the application genuinely needs cross-site inclusion; pair it with secure: true.
Default Uses the browser’s default handling rather than an explicitly selected policy. Use only if relying on browser defaults is intentional.

These request rules are summarized in MDN’s Set-Cookie reference. “Cross-site” behavior depends on the context of the request: a top-level navigation is different from a fetch, iframe, or other embedded resource request.

Why a Puppeteer cookie may be missing cross-site

A cookie can be set successfully and still be excluded from a particular request. Check these causes in order:

  1. The request type does not qualify. Lax can cover eligible top-level safe navigations, but not typical cross-site fetches, embedded resources, or unsafe methods. For a real cross-site use case, try sameSite: 'None' with secure: true.
  2. The cookie was set in a different context. Set it on the browser context used by the page making the request, or use Browser.setCookie() if the default context is intended.
  3. The cookie scope does not match. Verify its URL or domain and path, along with expiry and other attributes. SameSite does not override those restrictions.
  4. The cookie relies on an omitted value. Chromium uses Lax as its default, but defaults can differ among browsers. Set the intended value explicitly when consistency matters. See MDN’s third-party cookie guidance.
  5. The browser blocks third-party cookies. SameSite=None does not guarantee acceptance or transmission in every browser; separate third-party-cookie policies may still apply.

Security attributes are separate

SameSite can reduce some cross-site request forgery (CSRF) exposure, but it is not a complete CSRF defense. For session cookies, consider HttpOnly and Secure for their distinct purposes: HttpOnly prevents access through client-side scripts, while Secure restricts transmission to secure connections. Neither changes the site-boundary rules controlled by SameSite.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is a website screenshot rather than testing cookie behavior in Puppeteer, ScreenshotNeo returns a screenshot or PDF from one GET request. Cookie banners are accepted and removed before capture, along with known newsletter popups and chat widgets; those cleanup steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000.

cURL example (replace the target URL as needed; see the ScreenshotNeo API documentation):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Sign up for 1,000 free screenshots a month, with no card required.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.