Cookies
| Set a cookie | |
| Read Array | |
| Expiry, path and flags | |
| Delete a cookie |
Set a cookie
Call setcookie before any output to store a small value in the browser.
The browser then sends that value back on every later request to a matching path. Background in
PHP cookies.
Keep cookies tiny and never store passwords or permissions inside them.
setcookie("theme", "dark"); echo "preference saved";
Read $_COOKIE
On the next request PHP fills $_COOKIE with values the browser chose to send.
A cookie set in the current request is not yet visible there.
Always provide a default, since users can clear or block cookies at any time.
$theme = $_COOKIE["theme"] ?? "light"; echo $theme;
Expiry, path and flags
The options array controls lifetime, scope, and safety flags. Set an expiry timestamp for
persistence, a path for scope, and secure flags for protection.
Modern defaults favor httponly and samesite protections.
setcookie("theme", "dark", [ "expires" => time() + 60 * 60 * 24 * 30, "path" => "/", "secure" => true, "httponly" => true, "samesite" => "Lax", ]);
Delete a cookie
There is no separate delete call. Send the same cookie again with an expiry time in the past
and an empty value, using the same path and domain as when it was created.
After deletion the browser stops sending the value on the following requests.
setcookie("theme", "", [ "expires" => time() - 3600, "path" => "/", ]); echo "preference cleared";
Next: Sessions
Article author: Arthur Isaev