Privacy & Transparency

Cookies & Storage

Everything Hi, Mexa stores in your browser — what it is, why we use it, and how long it lasts.

Session cookies

Set by our server, marked httpOnly and Secure. Strictly necessary to keep you signed in.

EssentialNot set

himexa.auth.session-token

Short-lived session token (JWT) used to authorize your requests to the backend through the server-side proxy. Without it you cannot stay signed in.

httpOnly
Yes
Secure
Yes
SameSite
Lax
Path
/
Expiry
Session — mirrors the session-token TTL; cleared on logout.
EssentialNot set

himexa.auth.session-refresh

Session renewal token used server-side to silently obtain a new session token when the current one expires, so you are not logged out mid-session.

httpOnly
Yes
Secure
Yes
SameSite
Lax
Path
/
Expiry
Persistent — mirrors the session-refresh TTL; cleared on logout.
EssentialNot set

himexa.auth.challenge-token

Temporary challenge token that bridges the login step and MFA verification. Removed as soon as verification succeeds.

httpOnly
Yes
Secure
Yes
SameSite
Lax
Path
/
Expiry
Short-lived — expires with the MFA challenge or on success.

Cookie preferences

Manage your analytics consent for this browser.

Current choice:Not decided

Essential cookies are always active — they keep you signed in and cannot be turned off. Analytics helps us understand how the app is used. You can accept or decline it below at any time.

Cookies visible to JavaScript

Live snapshot from your browser for this site.

Reading your browser…

Browser storage on this device

Analytics and consent identifiers (not cookies).

Reading your browser…

We use cookies

Essential cookies keep you signed in. With your permission we also use Google Analytics to understand how the app is used and improve it. See our Privacy Policy and Cookies page.