Is there any way to set a cookie that is not readable on subdomains? In other words, have the cookie available on domain.com, but not
domain.com
It is not possible as the cookie domain is tail matched against the domain name. You will have to go with www.