1. Request Configuration
Fetch Client⚙️ Cookie Attributes & Scoping Options Configurable
.apps.godainfotech.in for subdomain sharing
2. Live Response & Cookie Inspector
// Press "Set Cookie" or "Get Cookie" to execute API call...
Single Frontend • Multi-Backend API Cookie Synchronization Lab
https://fa.apps.godainfotech.in
.apps.godainfotech.in for subdomain sharing
// Press "Set Cookie" or "Get Cookie" to execute API call...
| Time | Action | Target Server | HTTP Status | Cookie Name | Cookie Value | Scoping / Details |
|---|---|---|---|---|---|---|
| No test requests executed yet. Click a button above to begin. | ||||||
If Domain is omitted in Set-Cookie, the cookie is Host-Only: it will only be sent to the exact backend that issued it (e.g. api-ba-na).
If Domain=.apps.godainfotech.in is set, the browser shares the cookie with all subdomains (fa..., api-ba-na..., api-ba-eu...).
HttpOnly prevents JavaScript from reading the cookie via document.cookie (mitigating XSS).
To send/receive cookies in cross-origin fetch() requests, the client MUST include credentials: 'include'.
When credentials: 'include' is used, the backend CANNOT use Access-Control-Allow-Origin: *.
The backend must explicitly reflect the requesting origin (e.g. https://fa.apps.godainfotech.in) and set Access-Control-Allow-Credentials: true.