---
title: Persistent Cookie Decision node
description: Checks for the existence of a specified persistent cookie, the default being session-jwt.
component: auth-node-ref
version: 7.4
page_id: auth-node-ref::persistent-cookie-decision
canonical_url: https://docs.pingidentity.com/auth-node-ref/latest/persistent-cookie-decision.html
llms_txt: https://docs.pingidentity.com/auth-node-ref/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
keywords: ["Nodes &amp; Trees", "Journeys", "Authentication", "HMAC", "JSON"]
page_aliases: ["auth-node-persistent-cookie-decision.adoc"]
superseded_by: https://docs.pingidentity.com/auth-node-ref/latest/persistent-cookie-decision.html
section_ids:
  compatibility: Compatibility
  outcomes: Outcomes
  properties: Properties
  example: Example
---

# Persistent Cookie Decision node

Checks for the existence of a specified persistent cookie, the default being `session-jwt`.

If the cookie is present, the node verifies the signature of the JWT stored in the cookie with the signing key specified in the HMAC signing key property.

If the signature is valid, the node decrypts the payload of the JWT. It uses the key pair specified in the Persistent Cookie Encryption Certificate Alias property, found in the AM admin UI under Realms > *Realm Name* > Authentication > Settings > Security. The global level is found under Configure > Authentication > Core Attributes > Security.

The decrypted JSON payload includes information, such as the UID of the identity and the client IP address. Enable Enforce Client IP to verify that the current IP address and the client IP address in the cookie are identical.

|   |                                                                                                                                                                                                                                             |
| - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | This node recreates the received persistent cookie, updating the value for the idle time property.Cookie creation properties for the [Set Persistent Cookie node](set-persistent-cookie.html) are therefore available in this node as well. |

## Compatibility

| Product                                    | Compatible?           |
| ------------------------------------------ | --------------------- |
| PingOne Advanced Identity Cloud            | [icon: check, set=fa] |
| ForgeRock Access Management (self-managed) | [icon: check, set=fa] |
| Ping Identity Platform (self-managed)      | [icon: check, set=fa] |

## Outcomes

* `True`

* `False`

Evaluation continues along the `True` outcome path if the persistent cookie is present and all the verification checks above are satisfied; otherwise, evaluation continues along the `False` outcome path.

## Properties

| Property                      | Usage                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Idle Timeout                  | Specifies the maximum amount of idle time allowed before the persistent cookie is invalidated, in hours. If no requests are received and the time is exceeded, the cookie is no longer valid.                                                                                                                                                                                                                                                                                         |
| Enforce Client IP             | When enabled, ensures that the persistent cookie is only used from the same client IP to which the cookie was issued.                                                                                                                                                                                                                                                                                                                                                                 |
| Use Secure Cookie             | When enabled, adds the `Secure` flag to the persistent cookie.If the `Secure` flag is included, the cookie can only be transferred over HTTPS. When a request is made over HTTP, the cookie is not made available to the application.                                                                                                                                                                                                                                                 |
| Use HTTP Only Cookie          | When enabled, adds the `HttpOnly` flag to the persistent cookie.When the `HttpOnly` flag is included, that cookie will not be accessible through JavaScript. According to [RFC 6265](https://www.rfc-editor.org/info/rfc6265#section-4.1.2.6), the `HttpOnly` flag, "instructs the user agent to omit the cookie when providing access to cookies via 'non-HTTP' APIs (for example, a web browser API that exposes cookies to scripts)."                                              |
| HMAC Signing Key *(required)* | Specifies a key to use for HMAC signing of the persistent cookie. Values must be base64-encoded and at least 256 bits (32 bytes) long.&#xA;&#xA;To consume the persistent cookies generated by the Set Persistent Cookie node, ensure they are using the same HMAC signing key.To generate an HMAC signing key, run one of the following commands:```bash
$ openssl rand -base64 32
```or```bash
$ cat /dev/urandom | LC_ALL=C tr -dc 'a-zA-Z0-9' | fold -w 32 | head -n 1|base64
``` |
| Persistent cookie name        | Specifies the name of the persistent cookie to check.                                                                                                                                                                                                                                                                                                                                                                                                                                 |

## Example

The following example authenticates the user based on a persistent cookie, if possible:

![The persistent cookie decision in context](_images/trees-node-persistent-cookie-decision-example-platform.png)
