Skip to content

Cookies

HTTP Cookie Configuration

Configuration for HTTP cookies used to maintain User-Agent state throughout the authorization flow. These settings conform to the cookies module interface specification. The maxAge and expires properties are ignored; cookie lifetimes are instead controlled via the ttl.Session and ttl.Interaction configuration parameters.


Keygrip signing keys used for cookie signing to prevent tampering. You may also pass your own KeyGrip instance.

recommendation: Rotate regularly (by prepending new keys) with a reasonable interval and keep a reasonable history of keys to allow for returning user session cookies to still be valid and re-signed.

default value:

[]

Options for long-term cookies.

default value:

{
httpOnly: true,
sameSite: 'lax'
}

Specifies the HTTP cookie names used for state management during the authorization flow.

default value:

{
interaction: '_interaction',
resume: '_interaction_resume',
session: '_session'
}

Options for short-term cookies.

default value:

{
httpOnly: true,
sameSite: 'lax'
}