| authjs.session-token (authjs.session-token with a __Secure- prefix once the site is served over https) | PurposeKeeps you signed in between page loads. | TypeNecessary | DurationSession, until you sign out; expires on its own after 30 days if you never return (Auth.js default). | ProviderApply in Denmark |
|---|
| authjs.csrf-token (__Host- prefixed over https) | PurposeProtects the Google sign-in form against a forged request from another site. | TypeNecessary | DurationOnly present during the sign-in flow itself. | ProviderApply in Denmark |
|---|
| authjs.callback-url (__Secure- prefixed over https) | PurposeRemembers which page to return you to after Google sign-in. | TypeNecessary | DurationOnly present during the sign-in flow itself. | ProviderApply in Denmark |
|---|
| authjs.pkce.code_verifier (__Secure- prefixed over https) | PurposeSecurity check that proves the sign-in reply came from the same browser that started signing in with Google. | TypeNecessary | Duration15 minutes, only present during the sign-in flow itself. | ProviderApply in Denmark |
|---|
| authjs.state (__Secure- prefixed over https) | PurposeProtects the Google sign-in redirect against a forged request from another site. | TypeNecessary | Duration15 minutes, only present during the sign-in flow itself. | ProviderApply in Denmark |
|---|
| aid_consent | PurposeRemembers your cookie choice, so we do not ask again on every visit. | TypeNecessary | DurationUp to 12 months, or until you change your choice. | ProviderApply in Denmark |
|---|
| aid.signedIn (stored in your browser's local storage, not as a cookie) | PurposeLets the account menu appear right away on your next visit instead of a moment later, by remembering that your last visit was signed in. Holds only a yes or no value, mirroring whether the session cookie above is present: no name, no mail, nothing that identifies you. | TypeNecessary | DurationUntil you sign out, or indefinitely if you never do (cleared automatically the moment you sign out). | ProviderApply in Denmark |
|---|
| _fbp | PurposeMeta advertising measurement: helps Meta connect an ad click to a later visit. Only set once you accept marketing cookies. | TypeMarketing | DurationUp to 90 days (set by Meta, not by us). | ProviderMeta |
|---|
| _fbc | PurposeMeta advertising measurement: records that you arrived from a Meta ad. Only set once you accept marketing cookies, and only if you arrived that way. | TypeMarketing | DurationUp to 90 days (set by Meta, not by us). | ProviderMeta |
|---|