| Cookie | Category | Purpose |
|---|---|---|
__Host-next-auth.csrf-token | Functional | Used to help with site security in preventing Cross-Site Request Forgery attacks. |
__Secure-next-auth.callback-url | Functional | Used to store the callback URL which the user should be redirected to after login. |
Running NextAuth.js on your site? A free Conzent scan shows which of these cookies are set before consent, and the banner blocks them until the visitor agrees.
Last updated 2026-09-27.