Set-Cookie
IANA permanent
response
reached by regulation
Declared by 37 providers across 505 published specification files in the APIs.io network.
A count here is providers whose published contract declares this header — not
providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low
number can measure documentation practice rather than deployment.
Reached by regulation
Basis: evidentiary.
No law names this header; it is the deployed control for an obligation that regulation does impose.
Observable at the edge, without credentials.
The registry
| Status | permanent |
|---|---|
| Reference | RFC-ietf-httpbis-rfc6265bis-22, Section 5.8.1: Cookies: HTTP State Management Mechanism |
Providers declaring it (37)
aleph-alpha amcs-group autodesk-fusion beehero cisco-nexus citrix-netscaler cloudquery cybereason devtron dream-sports euler hanko ibm-mq lakefs lenovo linkedin mcafee mist mist-ai netcracker opaque oracle-e-business-suite passbolt pred salesforce saml sap-business-one shopify shyft spacetrack sso tower trellix-web-gateway university-of-basel websphere windmill zoominfo
Explore
All headers Authentication Guidance on headers.apievangelist.com