RFC 6265: Nameless cookies use-cases

Hi all,

We've been looking at RFC6265bis draft for guidance on nameless cookies.

We see that RFC6265bis says that "servers MUST NOT produce nameless cookies (i.e.: an empty cookie-name) as such cookies may be unpredictably serialized by UAs when sent back to the server.” (Section 4.1.1)

The RFC does not prohibit clients from accepting them. Section 5.6 explicitly says that the name may be “possibly empty"

Safari has rejected nameless cookies for a while now. What are the observed use-cases of nameless cookies? Does anyone know of servers that send out such cookies and the motivations for doing so?

-Xyan

Received on Thursday, 25 June 2026 20:36:43 UTC