Search
Star
Feedback
Setup for Free
© 2026 Hedgehog Software, LLC
Twitter
GitHub
Discord
System
Light
Dark
More
Communities
Docs
About
Terms
Privacy
Storing JWT refresh token in httpOnly cookie - Theo's Typesafe Cult
TTC
Theo's Typesafe Cult
•
3y ago
•
17 replies
gustagol
Storing JWT refresh token in httpOnly cookie
So
, I
'm building the auth part of an application
. I have always return both
access
access
and
refresh
refresh
tokens on the payload
. And them have them stored separately on the client
.
Now
, after doing a little research
, I have found that some people return just the
access
access
token on the payload
, and have the
refresh
refresh
token set as an httpOnly cookie
.
What is the opinion on this
? Good practice
? Bad practice
? Unnecessary
/ anti pattern
? Thanks in advance
!
Theo's Typesafe Cult
Join
26,564
Members
View on Discord
Resources
ModelContextProtocol
ModelContextProtocol
MCP Server
Similar Threads
Was this page helpful?
Yes
No
Similar Threads
HttpOnly Cookie
TTC
Theo's Typesafe Cult / questions
3y ago
Storing and getting cookie in api
TTC
Theo's Typesafe Cult / questions
3y ago
Storing and retrieving cookie
TTC
Theo's Typesafe Cult / questions
3y ago
refresh token
TTC
Theo's Typesafe Cult / questions
4y ago