RFC 6265 · PROPOSED STANDARD · 2011

HTTP State Management Mechanism

Overview

RFC 6265, “HTTP State Management Mechanism”, is a Proposed Standard document published in April 2011 by A. Barth. It obsoletes RFC 2965. The canonical text is published by the RFC Editor.

Abstract

This document defines the HTTP Cookie and Set-Cookie header fields. These header fields can be used by HTTP servers to store state (called cookies) at HTTP user agents, letting the servers maintain a stateful session over the mostly stateless HTTP protocol. Although cookies have many historical infelicities that degrade their security and privacy, the Cookie and Set-Cookie header fields are widely used on the Internet. This document obsoletes RFC 2965. [STANDARDS-TRACK]

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 6265 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC obsoletes
RFC 2965
Other RFCs from 2011

Who Is Online

In total there are 23 users online: 0 registered, 17 guests and 6 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Bingbot Other Bot SemrushBot Sogou

Users active in the past 15 minutes. Total registered members: 354