---
title: "HeldCookie"
description: "one cookie of a held identity's session state, as the browser gave it"
section: concepts
address: /concepts/heldcookie
contract: 0476e35e6e275db5
---

# HeldCookie

one cookie of a held identity's session state, as the browser gave it

[figure: HeldCookie is a value at none scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | value |
| scope | none |
| key | none |
| store | none |
| family | sources |



## Fields


| field | type | required | note |
|---|---|---|---|
| `name` | `text` | yes |  |
| `value` | `text` | yes | never returned by a tool and never logged |
| `domain` | `text` | yes |  |
| `path` | `text` | yes |  |
| `expires` | `number` | no | seconds since the epoch; absent for a session cookie |
| `secure` | `bool` | yes |  |
| `http_only` | `bool` | yes |  |



## Routes that use it
No route takes or returns HeldCookie directly. The record holds it, and the objects that point at it reach it.
