Back to Glossary
HTTPOnly Cookie
.

HTTPOnly is a cookie security attribute that prevents client-side JavaScript from accessing the cookie's value. When flagged HttpOnly, a cookie can only be transmitted via HTTP/HTTPS requests — it cannot be read or modified by scripts running in the browser. This significantly reduces the risk of cross-site scripting (XSS) attacks stealing session cookies or authentication tokens. HTTPOnly is a security best practice endorsed by OWASP and is separate from GDPR consent requirements — it controls how a cookie is accessed, not whether consent is needed to set it. Session and authentication cookies are most commonly flagged HttpOnly.

Tracking Tech