SameSite Cookies

SameSite cookies help limit cross-site request leakage. Modes are Strict, Lax and None (None requires Secure).

SameSite cookie settings help browsers decide when to send cookies on cross-site requests.

  • Lax: good default for many apps
  • Strict: strongest, can break some flows
  • None: required for some SSO; must also be Secure