setCookie
Set a browser cookie.
Syntax​
cy.setCookie(name, value)
cy.setCookie(name, value, options)
Usage​
Correct Usage
cy.setCookie('auth_key', '123key') // Set the 'auth_key' cookie to '123key'
Arguments​
name (String)
The name of the cookie to set.
value (String)
The value of the cookie to set.
options (Object)
Pass in an options object to change the default behavior of cy.setCookie().
| Option | Default | Description |
|---|---|---|
log | true | Displays the command in the Command log |
domain | Hostname of the application under test | The domain the cookie is visible to. By default the resulting cookie is not host-only; it is matched for this host and all of its subdomains. To restrict the cookie to a single exact host, pass hostOnly: true. See Cookie scope. |
expiry | 20 years into the future | When the cookie expires, specified in seconds since Unix Epoch. |
hostOnly | false | Whether the cookie is a host-only cookie. When true, the cookie is scoped to one exact host (the request's host must exactly match the cookie's domain) and is not attached to requests for sibling or parent hosts. See Cookie scope. |
httpOnly | false | Whether the cookie is an HTTP only cookie |
path | / | The cookie path |
secure | false | Whether the cookie is a secure cookie |
timeout | responseTimeout | Time to wait for cy.setCookie() to resolve before timing out |
sameSite | undefined | Cookie's SameSite value. If set, should be one of lax, strict, or no_restriction. Pass undefined to use the browser's default. Note: no_restriction can only be used if the secure flag is set to true. |
Yields ​
cy.setCookie() yields a cookie object with the following properties:
domainexpiry(if specified)hostOnly(if specified)httpOnlynamepathsameSite(if specified)securevalue
Examples​
Name Value​
Set a cookie​
cy.getCookies().should('be.empty')
cy.setCookie('session_id', '189jd09sufh33aaiidhf99d09')
cy.getCookie('session_id').should(
'have.property',
'value',
'189jd09sufh33aaiidhf99d09'
)
Cookie scope (host-only vs. domain cookies)​
When you call cy.setCookie() without hostOnly, the domain defaults to the
hostname of the current URL, but the cookie is stored as a domain cookie,
not a host-only cookie. Internally Cypress rewrites the domain to its
leading-dot form (e.g. .app.example.com), mirroring how real browsers store a
cookie that omits the Domain attribute's host-only flag. As a result the
cookie matches that host and all of its subdomains.
This matters for cy.request(), which pulls
matching cookies from the cookie jar by domain match before sending a request.
Because the default cookie is a domain cookie, it can be attached to a
cy.request() aimed at a different host that domain-matches it, for example
a sibling host on the same registrable domain. This is working as designed, but
can be surprising when you set a convenience cookie for your app and see it
appear on an unrelated request.
cy.visit('https://app.example.com')
// Default: domain cookie, matches app.example.com AND its subdomains
cy.setCookie('cookieconsent_status', 'dismiss')
// Host-only: matches ONLY the exact host it was set on
cy.setCookie('cookieconsent_status', 'dismiss', { hostOnly: true })
If a cookie is unexpectedly attached to a cy.request() for another host on the
same registrable domain, set hostOnly: true to keep it scoped to a single
exact host.
Preserving a cookie across tests​
By default, Cypress
clears all cookies before each test to
keep tests independent. If you have a known cookie value that every test
requires — such as a cookie-consent acceptance or a feature flag — re-set it in
a beforeEach hook so it is present at the start of every test:
// cypress/support/e2e.js
beforeEach(() => {
cy.setCookie('cookieConsent', 'accepted')
})
For cookies that are generated by the server after a login flow, use
cy.session() instead, which caches and restores the
full browser context (cookies, localStorage, and sessionStorage) across tests.
Notes​
Default cookie domain before visiting a page​
The domain option defaults to the hostname of the application under test.
Before cy.visit() loads a page, the application under
test is on about:blank, so Cypress uses the hostname it serves the spec from
instead (usually localhost). Pass domain explicitly to work with cookies on
another domain before visiting.
Rules​
Requirements ​
cy.setCookie()requires being chained off ofcy.
Assertions ​
cy.setCookie()will only run assertions you have chained once, and will not retry.
Timeouts ​
cy.setCookie()can time out waiting for the browser to set the cookie. It waits up to theresponseTimeout(or thetimeoutoption, when passed) before failing.- If the application under test is on a different origin,
cy.setCookie()retries for up to thedefaultCommandTimeout(or thetimeoutoption, when passed) and then fails with a cross-origin error. Run it insidecy.origin()to work with cookies on that origin.
Command Log​
Set a cookie on the browser for testing
cy.getCookies().should('be.empty')
cy.setCookie('fakeCookie1', '123ABC')
cy.getCookie('fakeCookie1').should('have.property', 'value', '123ABC')
The commands above display in the Command Log as:

When clicking on setCookie within the command log, the console outputs the
following:

History​
| Version | Changes |
|---|---|
| 12.7.0 | Support hostOnly option for a given domain. |
| 5.0.0 | Removed experimentalGetCookiesSameSite and made sameSite property always available. |
| 4.3.0 | Added sameSite property when the experimentalGetCookiesSameSite configuration value is true. |
| 0.16.0 | cy.setCookie() command added |