Cookie Incident Operational Checklist

Cookie issues recur when handled ad hoc. A single format for triage, permanent remediation, and monitoring keeps operations stable.

When to use this checklist

15-minute triage (first pass)

  1. 1) Collect all Set-Cookie lines from failed responses with timestamp and URL
  2. 2) Use Set-Cookie Inspect to diff SameSite/Secure/Domain/Path attributes
  3. 3) Validate send decision for target URL with Cookie Domain/Path Matcher
  4. 4) If external navigation exists, reproduce cross-site behavior in SameSite Cookie Simulator
  5. 5) If name collisions are suspected, detect overlaps with Set-Cookie Conflict Checker

Symptom-to-fastest-route matrix

Permanent-fix checklist

Operations monitoring checklist

Related pages (recommended order)

FAQ

If I can check only one thing first, what should it be?
Start with factual Set-Cookie attributes. Without that baseline, SameSite/Domain/Path diagnosis is unreliable.
What most commonly recurs in operations?
Reintroduction of same-name cookies and legacy-cookie leftovers during migrations. Enforcing naming and cleanup in release workflow prevents recurrence.

Referenced specs

These links are generated from site_map rules in recommended diagnostic order.

  1. How to Diagnose Set-Cookie Not Persisting — Isolate cookie persistence failures by checking Domain/Path/Secure/SameSite in order
  2. How to Diagnose Lost Login After OAuth Return — Isolate cookie-delivery failures after IdP return across SameSite, Secure, Path/Domain, and collisions
  3. How to Diagnose Same-Name Cookie Collisions — Resolve unstable behavior by tracing same-name cookie path/domain variants, overwrite order, and send collisions
  4. How to choose cookie tools — Route Set-Cookie, Domain-Path, SameSite, conflict, and size checks by symptom
  5. Set-Cookie Inspect — Parse Set-Cookie attributes and review delivery policy
  6. Cookie Domain/Path Matcher — Evaluate cookie send conditions by Domain/Path/Secure
  7. SameSite Cookie Simulator — Simulate cookie send behavior from SameSite and request context
  8. Set-Cookie Conflict Checker — Detect same-name cookie conflicts and overwrite risks

Scenario Clusters

Operational incident scenarios that route you into the shortest diagnostic path