cypress cy.origin() with cy.session() not working together
Fixes Cypress cy.origin() not working together with cy.session() for QA engineers and agents. Use when a cached session from one origin is invisible inside cy.origin() of another. Not for single-origin session caching or for third-party cookie issues.
TL;DR
Sessions are scoped to the origin that created them, so a session saved on your app's domain does not exist inside cy.origin() for the auth provider's domain. Create the session inside the cy.origin() block on the provider origin, or restructure so the session is created and validated on the same origin. Fighting the scoping with workarounds just moves the bug.
The query
cypress cy.origin() with cy.session() not working togetherUse this when
- cy.session() is called on the app origin but login happens inside cy.origin()
- The session validates on one domain and the test needs it on another
- You see "session not found" or a fresh login prompt inside cy.origin()
Not for
- Caching a session on a single origin (that works fine)
- Third-party cookie blocking in the browser
- Multi-domain apps without an auth step
Steps
- Map which origin creates the session and which origin needs it. Write down the two origins and where each cy.session and cy.origin call runs.
Expected output: a diagram of origins versus session calls showing the mismatch.
- Move session creation inside cy.origin(). Call cy.session() within the cy.origin() block for the provider domain so the session is stored under that origin.
Expected output: the session created and validated on the provider origin, with login succeeding inside cy.origin().
- Or validate the session on the app origin instead. If the app accepts a token or cookie directly, create the session on the app origin and skip cy.origin() for login entirely.
Expected output: a session established on the app origin without entering cy.origin() at all.
- Keep one cross-origin login test. After restructuring, keep a single test that exercises the real cross-origin flow so regressions are caught.
Expected output: one dedicated cross-origin login test, green in CI.
- Run the full auth suite. Session scoping bugs often hide until tests run in sequence.
Expected output: the whole auth spec file green in one run, not just the edited test.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst3D7mSyRSkpqdGVD6UOarA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.