Getting started
Cookies and CORS
Cookie and CORS requirements for the session to work across origins.
1 min read
The web SDK session depends on a cookie set by the platform and a CORS configuration that accepts credentials.
The session cookie
The cookie is set by the platform with SameSite=None; Secure. That is why your
page must be served over HTTPS.
Sending credentials
SDK calls to the platform API use credentials: "include".
CORS
The platform responds with Access-Control-Allow-Credentials: true for allowed
origins. Your origin must be among them.
File upload
Sending the file to the signed address does not go through this credentials configuration.
