Having "Server Side Cookies" means that the Triggerbee visitor cookies are set by your own server instead of by the browser, so visitors stay recognized longer. The cookie domain is taken from your account's primary website domain. Requires a reverse proxy on your own domain.
BETA FEATURE
This feature is a work in progress, planned to be fully released at the end of 2026. This article will be updated continuously. Please contact [email protected] if you have any questions until then.
1. Set up your reverse proxy
Serve Triggerbee from your own domain instead of ours. You add one route to your site — /tb by default — that forwards those requests on to Triggerbee, passing along the visitor's IP address and the hostname they're browsing. How this is setup is dependent on your platform. In Cloudflare it can be done using a Worker with the following script.
// Serves Triggerbee from your own domain, so it's first-party
// Set PREFIX to where you want it mounted. Nothing else in this file needs changing
const PREFIX = '/tb';
const UPSTREAM = 'https://t.myvisitors.se';
const TRACKER_PATHS = /^\/(js(\/\d+)?|(3\/|4\/)?t|visitor-state\/[a-z-]+(\/[a-z-]+)*)$/;
const EVENT_PATHS = /^\/((3\/|4\/)?t)$/;
const SKIPPED_HEADERS = new Set([
'connection', 'keep-alive', 'proxy-authenticate', 'proxy-authorization',
'te', 'trailer', 'transfer-encoding', 'upgrade', 'host',
]);
export default {
async fetch(request, env) {
const url = new URL(request.url);
if (url.pathname !== PREFIX && !url.pathname.startsWith(`${PREFIX}/`)) {
return fetch(request);
}
const path = url.pathname.slice(PREFIX.length) || '/';
if (!TRACKER_PATHS.test(path)) {
return fetch(request);
}
const headers = new Headers();
for (const [name, value] of request.headers) {
if (!SKIPPED_HEADERS.has(name.toLowerCase())) {
headers.set(name, value);
}
}
headers.set('X-Forwarded-Host', url.host);
headers.set('X-Forwarded-Proto', url.protocol.replace(':', ''));
headers.set('X-Client-IP', request.headers.get('CF-Connecting-IP') ?? '');
// Always ours, never copied from the request: the key is what will tell Triggerbee this IP came from your proxy.
headers.delete('X-TB-Proxy-Key');
if (env && env.TB_PROXY_KEY) {
headers.set('X-TB-Proxy-Key', env.TB_PROXY_KEY);
}
const upstream = new URL(path + url.search, UPSTREAM);
let response;
try {
response = await fetch(upstream, {
method: request.method,
headers,
body: request.method === 'GET' || request.method === 'HEAD' ? undefined : request.body,
redirect: 'manual',
});
} catch {
return new Response('', { status: 502 });
}
const out = new Headers(response.headers);
out.delete('set-cookie');
for (const cookie of response.headers.getSetCookie()) {
out.append('set-cookie', cookie);
}
if (EVENT_PATHS.test(path)) {
out.set('cache-control', 'no-store');
}
return new Response(response.body, { status: response.status, headers: out });
},
};
Check it before moving on: open https://yourdomain.com/tb/js?site_id=YOUR_SITE_ID in a browser. You should get JavaScript back.
2. Change tracking code
Point the Triggerbee snippet at your own domain — replace the Triggerbee host https://t.myvisitors.se in the script URL with https://yourdomain.com/tb. Nothing else in the snippet changes.
Tracking carries on exactly as before; this only changes where the script is downloaded from. Reload your site and confirm in the browser's network tab that the Triggerbee script now loads from your own domain.
3. Turn on server-side cookies under account settings
With the first two steps in place, enable Server-side cookies in Account settings. Triggerbee will then set its cookies from your server instead of from the browser.
Your existing visitors are carried over automatically the next time they load a page. Nothing is lost and there's nothing for you to do.
Turning it off again is a one-way door: the visitor history the server has been keeping is lost. Only switch it off if you're prepared to start that history over.
