laravel/framework · error · RuntimeException

Cookie jar has not been set.

Error message

Cookie jar has not been set.

What it means

Thrown by SessionGuard::getCookieJar() when $this->cookie has never been assigned via setCookieJar(). The session guard queues remember-me and re-login cookies through a CookieJar; if the jar was not injected (typically by the Service Provider), any operation needing it fails.

Solutions

  1. Use the standard HTTP kernel/auth service provider so setCookieJar() is wired automatically.
  2. If constructing the guard manually, call $guard->setCookieJar(app(CookieJar::class)).
  3. Avoid triggering cookie-dependent auth operations (remember me, device logout) in non-HTTP contexts.
  4. In tests, resolve the guard from the container rather than new-ing it directly.

Example fix

// before — manual guard in a test, no cookie jar
$guard = new SessionGuard('web', $provider, session());
$guard->login($user, true); // RuntimeException: Cookie jar has not been set.

// after — inject the jar
$guard = new SessionGuard('web', $provider, request()->session());
$guard->setCookieJar(app(\Illuminate\Cookie\CookieJar::class));
$guard->login($user, true);
// or simply resolve from the container: $guard = Auth::guard('web');
Defensive patterns

Strategy: validation

Validate before calling

// PHP — resolve the guard from the container (jar is wired automatically)
$guard = Auth::guard('web'); // do not `new SessionGuard(...)` directly
// If you must construct manually:
if (! isset($guard->getCookieJar())) { /* only call after setCookieJar */ }

Type guard

// Heuristic guard for non-HTTP contexts: skip cookie-dependent operations
function guardHasCookieJar(\Illuminate\Auth\SessionGuard $g): bool {
    try { $g->getCookieJar(); return true; }
    catch (\RuntimeException) { return false; }
}

Try / catch

try {
    $guard->login($user, $remember);
} catch (\RuntimeException $e) {
    if (str_contains($e->getMessage(), 'Cookie jar')) {
        $guard->setCookieJar(app(\Illuminate\Cookie\CookieJar::class));
        $guard->login($user, $remember);
    } else throw $e;
}

Prevention

When it happens

Trigger: Using the SessionGuard outside the normal HTTP kernel wiring (e.g. in a queue worker, console command, or test) where the AuthServiceProvider's call to setCookieJar() did not run, and then invoking a path that needs cookies (login with remember, device logout with cookies).

Common situations: Instantiating SessionGuard manually in a test without calling setCookieJar(); running auth flows inside a queued job/artisan command that bypasses the cookie middleware; a custom service provider that overrides the session guard creation and forgets to inject the jar.

Related errors


AI-assisted analysis of laravel/framework@e0f6eb3518 (2026-08-11). Data as JSON: /api/errors/76075dd8ec67e636. Report an issue: GitHub.

Appendix: source

Thrown at src/Illuminate/Auth/SessionGuard.php:932

     */
    public function setRememberDuration($minutes)
    {
        $this->rememberDuration = $minutes;

        return $this;
    }

    /**
     * Get the cookie creator instance used by the guard.
     *
     * @return \Illuminate\Contracts\Cookie\QueueingFactory
     *
     * @throws \RuntimeException
     */
    public function getCookieJar()
    {
        if (! isset($this->cookie)) {
            throw new RuntimeException('Cookie jar has not been set.');
        }

        return $this->cookie;
    }

    /**
     * Set the cookie creator instance used by the guard.
     *
     * @param  \Illuminate\Contracts\Cookie\QueueingFactory  $cookie
     * @return void
     */
    public function setCookieJar(CookieJar $cookie)
    {
        $this->cookie = $cookie;
    }

    /**
     * Get the event dispatcher instance.

View on GitHub (pinned to e0f6eb3518)