Handling the 7-Day Cookie Cap: Engineering for Safari's ITP
Stop losing Safari users to the 7-day session cap. Learn how ITP limits client‑side cookies and how to use server‑side Set‑Cookie and the Storage Access API to maintain persistence.
23 Dec 2025, 12:04 UTC

The Disappearing Session Problem
You have a user who logs into your application, checks a "Remember Me" box, and expects to stay authenticated for 30 days. However, after exactly one week, they are suddenly booted back to the login screen. This isn't a bug in your server-side session logic; it is the intended behavior of Safari's Intelligent Tracking Prevention (ITP).
ITP is a privacy framework in WebKit that aggressively limits the lifespan of client‑side cookies to prevent long‑term cross‑site tracking. The critical takeaway for engineers is that any cookie set via document.cookie (JavaScript) is capped at a 7‑day expiration, regardless of the Expires or Max‑Age attribute you provide. In some cases, if the domain is flagged as a tracker, this window shrinks even further.
First‑Party vs. Third‑Party Contexts
To solve this, you first need to identify how your cookies are being delivered. Safari treats cookies differently based on the context of the request:
- First‑Party Cookies: Set by the domain currently appearing in the browser's address bar. These are generally more permissive but still subject to the 7‑day JS cap.
- Third‑Party Cookies: Set by a domain other than the one in the address bar (e.g., an iframe or an external API call). These are blocked by default in Safari.
If your authentication relies on a separate identity provider (IdP) domain, your session cookies are likely being treated as third‑party and blocked entirely, or capped aggressively by ITP.
The Solution: Server‑Side Set‑Cookie
The most effective way to bypass the 7‑day ITP cap is to move cookie creation from the client to the server. ITP specifically targets cookies created via the document.cookie API. Cookies set via the HTTP Set‑Cookie header from the server are treated as more trustworthy and can maintain longer expiration dates.
Implementation Comparison
| Method | Implementation | ITP Expiration |
|---|---|---|
| Client‑Side JS | document.cookie = "session=123; max‑age=2592000" |
Capped at 7 Days |
| Server‑Side Header | Set‑Cookie: session=123; Max‑Age=2592000; HttpOnly |
Respected (usually) |
Handling Cross‑Domain Access with Storage Access API
If your application must access cookies from a different domain (e.g., a shared SSO portal embedded in an iframe), you cannot rely on the cookie being there by default. You must use the Storage Access API. This API allows a third‑party frame to request permission from the user to access its own first‑party cookies.
Example Implementation:
// Run this inside the third‑party iframe context
async function requestCookieAccess() {
try {
// Check if we already have access
const hasAccess = await document.hasStorageAccess();
if (!hasAccess) {
// This MUST be triggered by a user gesture (e.g., a button click)
await document.requestStorageAccess();
console.log("Access granted to third‑party cookies");
} else {
console.log("Already have access");
}
} catch (err) {
console.error("Storage Access denied or not supported:", err)
}
}
Critical Risk: Calling requestStorageAccess() without a direct user interaction (like a click event) will result in an immediate rejection by the browser.
Limitations and Verification
Even with server‑side cookies, ITP is an evolving system. It uses on‑device machine learning to identify tracking patterns. If your domain exhibits behavior typical of a tracker (e.g., frequent redirects or cross‑site requests to unknown domains), Safari may still throttle your cookie persistence.
How to verify your session lifespan:
- Open Safari and navigate to your app.
- Open Web Inspector > Storage tab > Cookies.
- Set a cookie via JavaScript and observe the
Expirescolumn. - Set a cookie via the server
Set‑Cookieheader and compare the expiration date. - To test the 7‑day cap without waiting a week, you can use the
Delete All Website Dataoption in Safari settings to clear the state and re‑test your logic.
Actionable Summary
To ensure your users stay logged in on Safari, stop using document.cookie for session management. Shift your authentication tokens to HttpOnly cookies set via server‑side headers. For cross‑domain requirements, implement the Storage Access API triggered by a clear user action.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.