It feels like you should send a cookie in the right shape from the consumer side to verify that the consumer is actually sending the cookie, and in the provider state, you configure your verification to accept the cookie. I admit this isn't super ergonomic, so perhaps the pact docs have a better approach?