Sign In

Cookie & Session Security Policy

Effective Date: September 30, 2026 · Transparent disclosure of all functional and security cookies.

1. Essential Security & Functional Cookies

Our Single Sign-On service uses strictly essential cookies required for cryptographic authentication, session integrity, CSRF prevention, and responsive UI customization. We do not use any third-party advertising, profiling, or tracking cookies.

Cookie Name Purpose & Security Scope Attributes Duration
sso_access_token Short-lived encrypted RS256 JWT access token used to verify identity on authenticated requests. HttpOnly, Secure, SameSite=Lax 15 minutes
sso_refresh_token Cryptographically signed rolling refresh token used to securely reissue access tokens upon expiration. HttpOnly, Secure, SameSite=Lax 30 days
XSRF-TOKEN Anti-CSRF protection token synchronizing browser forms with server-side validation filters. Secure, SameSite=Lax Session / 30 days
sso_ctx Temporary encrypted OIDC authorization context holding callback targets, PKCE challenges, and display modes. HttpOnly, Secure, SameSite=Lax 5 minutes
sso_user / kh_user Serialized non-sensitive user identity claims (displayName, email, avatar) to render client navigation badges. Secure, SameSite=Lax 30 days
oauth_state_* Cryptographic anti-replay state token generated during social logins (Google, Telegram, Facebook, X). HttpOnly, Secure, SameSite=Lax 10 minutes
sso_theme / sso-theme Stores your active visual mode preference (System Auto, Light, or Dark) across all subdomains. SameSite=Lax 1 year

2. Modern Browser Protections & Silent Checks

Modern privacy standards (including Apple Safari ITP and Google Chrome Privacy Sandbox) restrict third-party cookie access inside cross-domain embedded iframes. For seamless authentication without page reload, our client SDK prioritizes the Seamless Popup Window protocol over legacy third-party iframe session checks.