Security Guides Security Audits
Frontend Security • Apr 2026

Browser Cookie Security Flags: HttpOnly, Secure, SameSite, and Prefixing

Master cookie security flags and __Host- / __Secure- prefixes to protect session identifiers from XSS and network sniffing.


Leveraging Cookie Name Prefixes

Using the __Host- cookie name prefix guarantees that cookies are locked to the exact domain origin, requiring HTTPS and a root path.