Legal

Cookie Declaration

This table lists active cookies and related storage technologies currently used in SaaS Foundations Demo.

Effective date:
February 24, 2026
Last updated:
February 25, 2026

No optional categories are currently active in this release. The table still includes required technologies needed for core service operation.

Cookie declaration table listing categories, services, identifiers, providers, storage, duration, and purpose.
CategoryRequiredServiceIdentifier keyStorage typeProviderPartyDurationPurpose
NecessaryYes
Authentication and session security
Keeps signed-in sessions secure and maintains core account access.
__Host-authjs.csrf-tokenCookieSaaS Foundations Demo (Auth.js)First-partySession (secure context only)Secure CSRF token variant used in HTTPS contexts.
NecessaryYes
Authentication and session security
Keeps signed-in sessions secure and maintains core account access.
__Secure-authjs.callback-urlCookieSaaS Foundations Demo (Auth.js)First-partySession (secure context only)Secure callback URL variant used in HTTPS contexts.
NecessaryYes
Authentication and session security
Keeps signed-in sessions secure and maintains core account access.
__Secure-authjs.session-tokenCookieSaaS Foundations Demo (Auth.js)First-partySession (secure context only)Secure session token variant used in HTTPS contexts.
NecessaryYes
Authentication and session security
Keeps signed-in sessions secure and maintains core account access.
authjs.callback-urlCookieSaaS Foundations Demo (Auth.js)First-partySessionStores the post-authentication return URL for Auth.js flows.
NecessaryYes
Authentication and session security
Keeps signed-in sessions secure and maintains core account access.
authjs.csrf-tokenCookieSaaS Foundations Demo (Auth.js)First-partySessionProtects Auth.js form submissions against cross-site request forgery.
NecessaryYes
Authentication and session security
Keeps signed-in sessions secure and maintains core account access.
authjs.session-tokenCookieSaaS Foundations Demo (Auth.js)First-partySession (rotated while active)Maintains authenticated session state for signed-in users.
NecessaryYes
Cookie preference state and replay reliability
Stores consent choices and reliability metadata used for replay and cross-tab sync.
sf_consentCookieSaaS Foundations DemoFirst-party180 daysPersists cookie consent state, consent context ID, and consent version.
NecessaryYes
Cookie preference state and replay reliability
Stores consent choices and reliability metadata used for replay and cross-tab sync.
sf-consent-audit-queue:v2Local storageSaaS Foundations DemoFirst-partyUp to 7 days (auto-pruned)Temporarily stores signed replay tokens when audit persistence must retry.
NecessaryYes
Cookie preference state and replay reliability
Stores consent choices and reliability metadata used for replay and cross-tab sync.
sf-consent-sync-eventLocal storageSaaS Foundations DemoFirst-partyEphemeral (overwritten on updates)Broadcasts consent updates across tabs when BroadcastChannel fallback is needed.
NecessaryYes
Signup abuse prevention
Protects signup flow from automated abuse with security checks.
cf-turnstile-responseToken / requestCloudflare TurnstileThird-partySingle request / short-lived challengeValidates that signup requests are human and mitigates abuse.
NecessaryYes
Theme preference
Stores light/dark/system preference for accessibility and UX continuity.
themeCookieSaaS Foundations DemoFirst-party1 yearPersists display theme preference across visits.
NecessaryYes
Theme preference
Stores light/dark/system preference for accessibility and UX continuity.
themeLocal storageSaaS Foundations DemoFirst-partyPersistent until changed or clearedAllows theme resolution before hydration and across sessions.