--- layout: default ---

Set-Cookie

IANA permanent response reached by regulation

Declared by 37 providers across 505 published specification files in the APIs.io network.

What this header is for, and how to use it →

A count here is providers whose published contract declares this header — not providers who send it. Response headers set at the edge rarely appear in an OpenAPI at all, so a low number can measure documentation practice rather than deployment.

Reached by regulation

Basis: evidentiary. No law names this header; it is the deployed control for an obligation that regulation does impose. Observable at the edge, without credentials.

eprivacy-directive gdpr

The registry

Statuspermanent
ReferenceRFC-ietf-httpbis-rfc6265bis-22, Section 5.8.1: Cookies: HTTP State Management Mechanism

Providers declaring it (37)

aleph-alpha amcs-group autodesk-fusion beehero cisco-nexus citrix-netscaler cloudquery cybereason devtron dream-sports euler hanko ibm-mq lakefs lenovo linkedin mcafee mist mist-ai netcracker opaque oracle-e-business-suite passbolt pred salesforce saml sap-business-one shopify shyft spacetrack sso tower trellix-web-gateway university-of-basel websphere windmill zoominfo

Explore

All headers Authentication Guidance on headers.apievangelist.com