Cookie HttpOnly Secure SameSite Path Max-Age
osprey_access Yes configurable Strict /api/ 900 (15m)
osprey_refresh Yes configurable Strict /api/v1/auth/ 604800 (7d)

The osprey_access cookie contains a JWT with user claims (user_id, username, role, expiry). The osprey_refresh cookie is used to obtain new access tokens.