User Agent == Set-Cookie: lang=en-US; Expires=Wed, 09 Jun 2021 10:18:14 GMT == User Agent -> Server == Cookie: SID=31d4d96e407aad42; lang=en-US Finally, to remove a cookie, the server returns a Set-Cookie header with an expiration date in the past. Setting up a cookie-free domain seems like a hard task but believe me it's not. So can set a cookie for far so good. Is there a way to specify domain or even wildcard domain while getting the cookie in express handler? Quoting from the same RFC2109 you read: * A Set-Cookie from request-host for would be accepted. Notice the period before the domain name, this is very important.

