Cookies Settings | Pomerium (2024)

This reference covers all of Pomerium's Cookies Settings:

  • Cookie Name
  • Cookie Secret
  • Cookie Domain
  • Cookie HTTP Only
  • Cookie Expiration
  • Cookie SameSite
  • Cookie Secret File

Cookie Name

Cookie Name sets the name of the session cookie sent to clients.

How to configure

  • Core
  • Enterprise
  • Kubernetes
Config file keysEnvironment variablesTypeDefault
cookie_nameCOOKIE_NAMEstring_pomerium

Examples

cookie_name: cookie_name
COOKIE_NAME=cookie_name

Cookie Secret

Cookie Secret is the secret used to encrypt and sign session cookies. If you don't provide a cookie secret, Pomerium will generate one for you.

How to configure

  • Core
  • Enterprise
  • Kubernetes
Config file keysEnvironment variablesTypeUsage
cookie_secretCOOKIE_SECRETstringoptional

Examples

Generate a random, base64-encoded key:

head -c32 /dev/urandom | base64

Add the value to your configuration:

cookie_secret: tdkuWzUelRukP/6VYzopfh6kis7y5u5Ldl3MrIq9ZR0=
COOKIE_SECRET=tdkuWzUelRukP/6VYzopfh6kis7y5u5Ldl3MrIq9ZR0=

Cookie Domain

Cookie Domain sets the scope of session cookies issued by Pomerium.

If you specify the domain explicitly, then subdomains would also be included.

How to configure

  • Core
  • Enterprise
  • Kubernetes
Config file keysEnvironment variablesTypeUsageDefault
cookie_domainCOOKIE_DOMAINstringoptionalThe host that set the cookie

Examples

cookie_domain: localhost.pomerium.io
COOKIE_DOMAIN=localhost.pomerium.io

Cookie HTTP Only

If true, Cookie HTTP Only forbids JavaScript from accessing the cookie.

How to configure

  • Core
  • Enterprise
  • Kubernetes
Config file keysEnvironment variablesTypeDefault
cookie_http_onlyCOOKIE_HTTP_ONLYbooleantrue

Examples

cookie_http_only: false
COOKIE_HTTP_ONLY=false

Cookie Expiration

Cookie Expiration sets the lifetime of session cookies. After this interval, users must reauthenticate.

How to configure

  • Core
  • Enterprise
  • Kubernetes
Config file keysEnvironment variablesTypeDefault
cookie_expireCOOKIE_EXPIREstring (Go Duration formatting)14h

Examples

cookie_expire: 13h15m0.5s
COOKIE_EXPIRE=13h15m0.5s

Cookie SameSite

Cookie SameSite sets the SameSite option for cookies, which determines whether or not a cookie is sent with cross-site requests.

How to configure

  • Core
  • Enterprise
  • Kubernetes
Config file keysEnvironment variablesTypeUsageDefaultOptions
cookie_same_siteCOOKIE_SAME_SITEstringoptional Lax (if unset)See Cookie SameSite Options

Examples

cookie_same_site: Lax
COOKIE_SAME_SITE=Strict

Cookie SameSite options

| Attribute | Value || :-- | :-- | --- || Lax | The cookie is not sent on cross-site requests, such as on requests to load images or frames, but is sent when a user is navigating to the origin site from an external site (for example, when following a link). || Strict | The browser sends the cookie only for same-site requests, that is, requests originating from the same site that set the cookie. || None | The browser sends the cookie with both cross-site and same-site requests. If you set SameSite=none, the HTTPS only setting must be set to true. | |

Cookie Secret File

Cookie Secret File sets the path to the file containing a secret used to encrypt and sign session cookies.

How to configure

  • Core
  • Enterprise
  • Kubernetes
Config file keysEnvironment variablesTypeUsage
cookie_secret_fileCOOKIE_SECRET_FILEstringrequired (for proxy service)

Examples

Generate a random, base64-encoded key:

head -c32 /dev/urandom | base64

Add the value to your configuration:

cookie_secret_file: '/run/secrets/POMERIUM_COOKIE_SECRET'
COOKIE_SECRET_FILE='/run/secrets/POMERIUM_COOKIE_SECRET'

This is useful when deploying in environments that provide secret management like Docker Swarm.

Cookies Settings | Pomerium (2024)

FAQs

Where do I find the cookies settings? ›

In Chrome
  1. On your computer, open Chrome .
  2. At the top right, click More Settings .
  3. Click Privacy and security. Third-party cookies. Tip: If you are part of the Tracking Protection test group, follow the “Tracking Protection” instructions instead.
  4. Select an option: Allow third-party cookies.

How do I turn off cookies in Chrome? ›

Select the Chrome menu icon. Select Settings > Site Settings > Cookies and site data. Deselect Allow sites to save and read cookie data (recommended).

What does it mean when a website uses cookies? ›

Cookies are small pieces of text sent to your browser by a website you visit. They help that website remember information about your visit, which can both make it easier to visit the site again and make the site more useful to you.

What are cookies on my computer? ›

What cookies are. Cookies are files created by websites you visit. By saving information about your visit, they make your online experience easier. For example, sites can keep you signed in, remember your site preferences, and give you locally relevant content.

Should cookie settings be on or off? ›

Enabling cookies is optional, but it's sometimes best to enable them on reputable sites that need to know your preferences. When enabled, you'll allow the sites you visit the chance to customize your browsing experience based on your behavior, habits, and preferences as a user.

How do I clear all cookies? ›

Delete all cookies
  1. On your Android device, open Chrome .
  2. At the top right, tap More. Settings.
  3. Tap Privacy and security. Delete browsing data.
  4. Choose a time range, like Last hour or All time.
  5. Check Cookies and site data and uncheck all other items.
  6. Tap Delete data. Delete.

Is it better to accept cookies or not? ›

It's a good idea to decline third-party cookies. If you don't decline, the website could sell your browsing data to third parties. Sharing your personal information with third parties without giving you any control over it could also leave you vulnerable. For one thing, you don't get to choose the third parties.

What happens if I don't accept cookies? ›

Remember, cookies contain your information, including what sites you browse, what products you clicked on, where you're located, and even login information. By not accepting cookies, you eliminate the chance a hacker could hijack your cookies and use the data inside to access sites while pretending to be you.

Should you delete cookies? ›

The cache can also cause issues when viewing new versions of previously visited web pages. Deleting the cache and cookies data regularly helps to troubleshoot, helps to increase the loading time of web pages, loads new versions of web pages and increases the performance of your computer.

What happens if you turn off cookies? ›

Here are some examples of what happens if you block all cookies: You may not be able to automatically sign in to a site because your saved username and password is deleted. Some web pages or features won't function. You may see a message on websites asking you to enable cookies for it to load.

Should I allow all cookies on my computer? ›

Accepting cookies can be risky even on a website that your browser or security solution deems safe. But that doesn't mean you should accept all cookies blindly, as some of the responsibility of protecting your privacy and security ultimately falls onto you, the user.

What happens when you remove all cookies from computer? ›

By clearing the cache and cookies you are telling your computer to forget all previous activity, settings, and information. It is the internet equivalent of “turning it off and back on again”.

Where is cookies folder located? ›

In general, to get to the Microsoft cookies folder in Windows 10 or 11, you can open the Run box, type shell:cookies, and press Enter. They're located in the INetCookies folder in the C: drive. Your cookies are located in the same folder if you use Windows 8 or Windows 8.1.

How do I find all my cookies? ›

In Google Chrome, click ⋮ → "Settings" → "Privacy and security" → "Cookies and other site data" → "See all site data and permissions". On Safari, click "Safari" → "Settings" → "Privacy" → "Manage Website Data…". On Firefox, click ☰ → "Settings" → "Privacy & Security" → "Manage data…".

Where is cookies on my phone? ›

Enabling cookies in Chrome for Android

Go to More menu > Settings > Site settings > Cookies. You'll find the More menu icon in the top-right corner. Make sure cookies are turned on.

Top Articles
Latest Posts
Article information

Author: Tyson Zemlak

Last Updated:

Views: 6126

Rating: 4.2 / 5 (63 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Tyson Zemlak

Birthday: 1992-03-17

Address: Apt. 662 96191 Quigley Dam, Kubview, MA 42013

Phone: +441678032891

Job: Community-Services Orchestrator

Hobby: Coffee roasting, Calligraphy, Metalworking, Fashion, Vehicle restoration, Shopping, Photography

Introduction: My name is Tyson Zemlak, I am a excited, light, sparkling, super, open, fair, magnificent person who loves writing and wants to share my knowledge and understanding with you.