To send a known cookie with one PHP cURL request, set CURLOPT_COOKIE to a semicolon-separated string such as session_id=abc123; theme=dark. To reuse cookies received from a server across requests, enable cURL’s cookie engine with CURLOPT_COOKIEFILE and CURLOPT_COOKIEJAR.
Send a cookie on a single request
Use CURLOPT_COOKIE when you already know the cookie name and value and want to include them in the outgoing request. The value is a cookie string in NAME=CONTENTS form; separate multiple pairs with semicolons.
<?php
$ch = curl_init('https://example.com/account');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_COOKIE => 'session_id=abc123; theme=dark',
]);
$response = curl_exec($ch);
if ($response === false) {
throw new RuntimeException(curl_error($ch));
}
curl_close($ch);
This explicitly sets the outgoing Cookie header, but it does not turn on cookie storage or automatically save cookies returned by the server. See the libcurl CURLOPT_COOKIE documentation.
Keep cookies between PHP cURL requests
For a session that needs cookies sent by the server, use a cookie file both to import stored cookies and to save cookies received during the request. CURLOPT_COOKIEFILE reads cookies and enables automatic cookie handling; CURLOPT_COOKIEJAR specifies where the in-memory cookie store is written when the handle is cleaned up.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
<?php
$cookieFile = __DIR__ . '/cookies.txt';
$ch = curl_init('https://example.com/login');
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_COOKIEFILE => $cookieFile,
CURLOPT_COOKIEJAR => $cookieFile,
]);
$response = curl_exec($ch);
if ($response === false) {
throw new RuntimeException(curl_error($ch));
}
// PHP 8+: write the cookie jar before the handle is destroyed.
curl_setopt($ch, CURLOPT_COOKIELIST, 'FLUSH');
curl_close($ch);
The cookie file can use Netscape or HTTP-style cookie-file format. The jar option alone does not import cookies: pair it with CURLOPT_COOKIEFILE when you need to read cookies saved by an earlier request. Details are in the CURLOPT_COOKIEFILE and CURLOPT_COOKIEJAR documentation.
Why flush before cleanup on PHP 8 and later?
PHP documents that, as of PHP 8.0.0, curl_close() is a no-op and does not destroy the handle. Since libcurl normally writes the cookie jar when the handle is cleaned up, explicitly set CURLOPT_COOKIELIST to FLUSH when the jar must be written before automatic destruction. See PHP cURL predefined constants.
Quick Recap
Rank #4
Rank #2
Choose the right cookie option
| Need | Option | What it does |
|---|---|---|
| Send a known cookie string | CURLOPT_COOKIE |
Sends the specified cookie pairs; does not enable the cookie engine. |
| Load cookies from a file | CURLOPT_COOKIEFILE |
Reads the file and enables automatic cookie handling. |
| Save cookies handled by the engine | CURLOPT_COOKIEJAR |
Names the file where the cookie store is written at handle cleanup. |
| Write the jar immediately | CURLOPT_COOKIELIST set to FLUSH |
Flushes cookie data to the jar before cleanup. |
Cookie behavior and common pitfalls
- Do not confuse sending with persistence.
CURLOPT_COOKIEsends the explicit string but does not store cookies from responses. Use the cookie engine for automatic handling. - Cookie scope is applied by the engine. Engine-managed cookies are matched against domain, path, and secure rules. An explicit
CURLOPT_COOKIEvalue is separate and can coexist with engine cookies. - Avoid duplicate names when combining methods. If the explicit cookie string and engine store contain cookies with the same name, libcurl may send both values. Avoid this ambiguity by using one source for each cookie.
- Protect the cookie file. Cookie contents can act as session credentials. Restrict file permissions and avoid storing the jar in a directory accessible to other users. The cookie-jar documentation warns that permissions and shared-directory access matter.
- JavaScript-created browser cookies are not automatic. cURL does not execute page JavaScript. If a cookie is created only by browser-side code, reproduce the relevant HTTP cookie exchange rather than expecting cURL to run that code.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

