TECHNOLOGY · SECURITY
HttpOnly cookies logo

HttpOnly cookies

Login sessions kept in cookies no script on the page can read, so a single injected script cannot walk off with your customers’ accounts.

WHAT IT IS

In plain words

When someone logs in, their session is stored in a cookie marked HttpOnly, Secure and SameSite. The browser sends it with every request but refuses to reveal it to any JavaScript running on the page.

WHAT IT SERVES

What it does for you

The prize in most web attacks is the session token: take it and you are that user. Keeping tokens out of reach of scripts removes the prize, so even a script that slipped through cannot steal accounts.

Secure means the cookie only ever travels over HTTPS; SameSite stops another site from using it on your behalf.

WHY WE USE IT

What it gives your system

  • Session tokens that no script on the page can read
  • Sent only over HTTPS, never in the clear
  • Protected against requests forged by other sites
  • Sessions that expire, and can be ended everywhere at once
LET'S BUILD

YOUR VISION.
OUR TECHNOLOGY.

Tell us what your business needs. We'll build the system around it.

START A CONVERSATION →

or email us at info@nilexdigitalsystems.com