1. Essential Security & Functional Cookies
Our Single Sign-On service uses strictly essential cookies required for cryptographic authentication, session integrity, CSRF prevention, and responsive UI customization. We do not use any third-party advertising, profiling, or tracking cookies.
| Cookie Name | Purpose & Security Scope | Attributes | Duration |
|---|---|---|---|
| sso_access_token | Short-lived encrypted RS256 JWT access token used to verify identity on authenticated requests. | HttpOnly, Secure, SameSite=Lax | 15 minutes |
| sso_refresh_token | Cryptographically signed rolling refresh token used to securely reissue access tokens upon expiration. | HttpOnly, Secure, SameSite=Lax | 30 days |
| XSRF-TOKEN | Anti-CSRF protection token synchronizing browser forms with server-side validation filters. | Secure, SameSite=Lax | Session / 30 days |
| sso_ctx | Temporary encrypted OIDC authorization context holding callback targets, PKCE challenges, and display modes. | HttpOnly, Secure, SameSite=Lax | 5 minutes |
| sso_user / kh_user | Serialized non-sensitive user identity claims (displayName, email, avatar) to render client navigation badges. | Secure, SameSite=Lax | 30 days |
| oauth_state_* | Cryptographic anti-replay state token generated during social logins (Google, Telegram, Facebook, X). | HttpOnly, Secure, SameSite=Lax | 10 minutes |
| sso_theme / sso-theme | Stores your active visual mode preference (System Auto, Light, or Dark) across all subdomains. | SameSite=Lax | 1 year |
2. Modern Browser Protections & Silent Checks
Modern privacy standards (including Apple Safari ITP and Google Chrome Privacy Sandbox) restrict third-party cookie access inside cross-domain embedded iframes. For seamless authentication without page reload, our client SDK prioritizes the Seamless Popup Window protocol over legacy third-party iframe session checks.