laravel/framework · error · RuntimeException
Cookie jar has not been set.
Error message
Cookie jar has not been set.
What it means
Thrown by SessionGuard::getCookieJar() when $this->cookie has never been assigned via setCookieJar(). The session guard queues remember-me and re-login cookies through a CookieJar; if the jar was not injected (typically by the Service Provider), any operation needing it fails.
Solutions
- Use the standard HTTP kernel/auth service provider so setCookieJar() is wired automatically.
- If constructing the guard manually, call $guard->setCookieJar(app(CookieJar::class)).
- Avoid triggering cookie-dependent auth operations (remember me, device logout) in non-HTTP contexts.
- In tests, resolve the guard from the container rather than new-ing it directly.
Example fix
// before — manual guard in a test, no cookie jar
$guard = new SessionGuard('web', $provider, session());
$guard->login($user, true); // RuntimeException: Cookie jar has not been set.
// after — inject the jar
$guard = new SessionGuard('web', $provider, request()->session());
$guard->setCookieJar(app(\Illuminate\Cookie\CookieJar::class));
$guard->login($user, true);
// or simply resolve from the container: $guard = Auth::guard('web'); Defensive patterns
Strategy: validation
Validate before calling
// PHP — resolve the guard from the container (jar is wired automatically)
$guard = Auth::guard('web'); // do not `new SessionGuard(...)` directly
// If you must construct manually:
if (! isset($guard->getCookieJar())) { /* only call after setCookieJar */ } Type guard
// Heuristic guard for non-HTTP contexts: skip cookie-dependent operations
function guardHasCookieJar(\Illuminate\Auth\SessionGuard $g): bool {
try { $g->getCookieJar(); return true; }
catch (\RuntimeException) { return false; }
} Try / catch
try {
$guard->login($user, $remember);
} catch (\RuntimeException $e) {
if (str_contains($e->getMessage(), 'Cookie jar')) {
$guard->setCookieJar(app(\Illuminate\Cookie\CookieJar::class));
$guard->login($user, $remember);
} else throw $e;
} Prevention
- Resolve SessionGuard from the container, not via new.
- Inject the CookieJar when constructing the guard manually.
- Avoid remember-me/device-logout flows in non-HTTP (queue/console) contexts.
When it happens
Trigger: Using the SessionGuard outside the normal HTTP kernel wiring (e.g. in a queue worker, console command, or test) where the AuthServiceProvider's call to setCookieJar() did not run, and then invoking a path that needs cookies (login with remember, device logout with cookies).
Common situations: Instantiating SessionGuard manually in a test without calling setCookieJar(); running auth flows inside a queued job/artisan command that bypasses the cookie middleware; a custom service provider that overrides the session guard creation and forgets to inject the jar.
Related errors
- The given password does not match the current password.
- Auth driver [ ] for guard [ ] is not defined.
- Auth guard [ ] is not defined.
- Authentication user provider
- CSRF token mismatch.
AI-assisted analysis of laravel/framework@e0f6eb3518 (2026-08-11).
Data as JSON: /api/errors/76075dd8ec67e636.
Report an issue: GitHub.
Appendix: source
Thrown at src/Illuminate/Auth/SessionGuard.php:932
*/
public function setRememberDuration($minutes)
{
$this->rememberDuration = $minutes;
return $this;
}
/**
* Get the cookie creator instance used by the guard.
*
* @return \Illuminate\Contracts\Cookie\QueueingFactory
*
* @throws \RuntimeException
*/
public function getCookieJar()
{
if (! isset($this->cookie)) {
throw new RuntimeException('Cookie jar has not been set.');
}
return $this->cookie;
}
/**
* Set the cookie creator instance used by the guard.
*
* @param \Illuminate\Contracts\Cookie\QueueingFactory $cookie
* @return void
*/
public function setCookieJar(CookieJar $cookie)
{
$this->cookie = $cookie;
}
/**
* Get the event dispatcher instance.View on GitHub (pinned to e0f6eb3518)