October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

Puppeteer CookieData: Cookie Fields Explained

Puppeteer 25.12.0 CookieData requires name, value, and domain. Learn how its optional scope, expiry, security, SameSite, and Chrome-specific fields work.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In Puppeteer 25.12.0, CookieData describes cookies set through the browser-level cookie API. Its required fields are name, value, and domain; the remaining fields are optional. For new code, set cookies with Browser.setCookie() or BrowserContext.setCookie(), not the obsolete Page.setCookie().

What CookieData represents

CookieData is the object type accepted by Puppeteer’s browser-level cookie-setting method. The browser method sets cookies in the default browser context; use a specific BrowserContext when the cookie belongs to that context. The reference for Puppeteer 25.12.0 lists the fields below. See the CookieData API reference and Browser.setCookie() API reference.

Field Required? Meaning
name Yes The cookie’s name.
value Yes The cookie’s value. Its application-specific meaning is determined by the site or application using it.
domain Yes in CookieData The domain associated with the cookie. Domain scope depends on cookie rules: a host-only cookie and one set with a Domain attribute do not necessarily cover the same hosts.
path No The path scope for requests that can receive the cookie. It is a routing scope, not a security boundary.
expires No Expiration date represented as a number in Puppeteer’s interface. If omitted, Puppeteer describes the cookie as a session cookie. It is not a Max-Age field.
httpOnly No When true, the cookie is excluded from non-HTTP cookie APIs such as browser scripting APIs. This is independent of secure.
secure No When true, the cookie is restricted to secure channels. It primarily protects confidentiality; it is not a guarantee against every integrity risk.
sameSite No The SameSite setting. Puppeteer’s documented values are Strict, Lax, None, and Default; browser behavior and policy can evolve.
partitionKey No Partition context for a partitioned cookie. Puppeteer documents a sourceOrigin and optional hasCrossSiteAncestor; support and mapping are browser-specific.
priority No Cookie priority. Puppeteer documents this as supported only in Chrome.
sourceScheme No The cookie’s source scheme. Puppeteer documents this as supported only in Chrome. Its Unset value is described as temporary compatibility behavior slated for removal.

Field definitions and browser-support notes are from the Puppeteer 25.12.0 CookieData reference. The browser-specific properties should not be assumed to behave identically in every browser.

CookieData and CookieParam are different types

CookieData is used by browser- or context-level cookie methods. CookieParam is the separate page-level parameter type. Both include name and value, but CookieParam makes domain optional and offers an optional url. Puppeteer says that url can affect default domain, path, and source scheme. Do not treat the two interfaces as interchangeable; check the method’s accepted type in the CookieParam reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Detail CookieData CookieParam
API level Browser or browser context Page-level type
domain Required Optional
url Not listed Optional; can supply defaults for domain, path, and source scheme

Set a cookie with the current API

Use the browser or context API rather than the obsolete page method. This example sets a cookie on the browser’s default context; replace the example domain and cookie data with values appropriate to the site you control or are authorized to test.

import puppeteer from 'puppeteer';

const browser = await puppeteer.launch();
try {
  await browser.setCookie({
    name: 'session_id',
    value: 'example-value',
    domain: 'example.com',
    path: '/',
    httpOnly: true,
    secure: true,
    sameSite: 'Lax'
  });

  const page = await browser.newPage();
  await page.goto('https://example.com');
  console.log(await page.cookies());
} finally {
  await browser.close();
}

To target a particular context, call context.setCookie(...cookies) on that BrowserContext instead. Puppeteer’s guide covers getting, setting, and deleting cookies: Cookies guide. The Page.setCookie() reference marks that page-level method obsolete and directs users to browser or context methods.

Choose fields by the behavior you need

Scope and lifetime

  • Use domain and path to describe where a cookie is applicable. Domain matching does not mean every domain string automatically includes all subdomains.
  • Use expires when you need an expiry date rather than a session cookie. A user agent may evict cookies before their stated expiry.
  • Do not rely on path to protect sensitive data. RFC 6265 explicitly cautions that Path is not a security boundary.

Access and transport

  • httpOnly: true prevents access through non-HTTP cookie APIs. RFC 6265 puts it plainly: “The HttpOnly attribute limits the scope of the cookie to HTTP requests.”
  • secure: true limits sending to secure channels. A cookie can be both HttpOnly and Secure; the attributes address different risks.
  • sameSite controls cross-site cookie behavior. Select a value that fits the site’s flow and verify it in the target browser rather than assuming identical policy everywhere.

These are foundational descriptions from RFC 6265, published in April 2011. They do not fully describe newer browser policies or partitioned-cookie behavior.

Partitioning and browser-specific fields

Use partitionKey only when working with a partitioned-cookie context supported by the browser. Puppeteer’s documented key includes sourceOrigin and may include hasCrossSiteAncestor. Treat this as browser-specific rather than portable cookie metadata. Similarly, Puppeteer documents priority and sourceScheme as Chrome-only. Avoid relying on sourceScheme: 'Unset' for new long-lived code; the reference describes it as temporary compatibility behavior slated for removal.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Troubleshooting cookie setup

  • TypeScript reports a missing field: For CookieData, supply name, value, and domain. Do not assume url can replace domain; that distinction belongs to CookieParam.
  • The cookie is not sent to the page: Check that the requested host and path match its domain and path scope, and check whether secure requires a secure connection. Confirm the page is using the browser context where the cookie was set.
  • Page.setCookie() is marked obsolete: Move the call to browser.setCookie() or context.setCookie(), choosing the context that owns the page.
  • A cookie appears to vanish before expiry: Expiration is not a retention guarantee; user agents may evict cookies earlier. Also verify the actual cookie jar and context rather than assuming a cookie set in one context is available in another.
  • Partition or source options behave differently across browsers: Puppeteer’s documentation identifies Chrome-specific support for several properties. Test against the actual browser and version you deploy, and do not assume those fields are portable.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is to capture a web page rather than automate cookie handling in Puppeteer, ScreenshotNeo is a website screenshot API and MCP server. One GET request can return a PNG, JPEG, WebP, or PDF; its capture flow accepts consent banners and removes known consent platforms, newsletter popups, and chat widgets before the shot. Bot checks, blank pages, failed loads, timeouts, and cache hits cost nothing, and response headers identify the page verdict and billing status. AI agents can use its MCP server tools, including take_screenshot, get_page_info, and capture_pdf.

See the ScreenshotNeo API documentation. Free includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000 screenshots.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp

Sign up for ScreenshotNeo’s free plan to get 1,000 screenshots a month with no card.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.