Legal · Authvio

Cookie Policy

The first-party browser storage used for Authvio authentication, registration, hosted verification, and developer-console state.

Last updated: July 18, 2026 · A brand of Bolrach Technologies Limited

On this page

1. What this policy covers

Cookies are small values a site asks a browser to return with later requests. This page also covers comparable first-party browser storage used by Authvio. The values usually contain a protected identifier or workflow state, not a readable copy of an identity document.

2. Why Authvio uses them

Authvio uses first-party storage to authenticate sessions, protect forms and redirects, bind verification actions to the right browser, and remember a developer's Test or Live display choice. These functions are needed to provide a requested account, authentication, or verification service. Authvio does not use advertising cookies or sell cookie identifiers.

3. Current first-party cookies

Cookie or groupPurposeMaximum or normal lifetime
authvio_oidcBinds the browser to an OIDC sign-in request and protects state, nonce, and PKCE continuity.10 minutes
__Host-authvio_sessionKeeps a signed-in Authvio session on the exact account or console host.Up to 7 days
__Host-authvio_presenceLets the Authvio homepage show that this browser has recently signed in. It grants no account access.Up to 30 days
Ory identity sessionKeeps the identity-provider session on id.authv.io. The generated cookie name is controlled by Ory Kratos.Up to 30 days
Ory flow and CSRF cookiesProtect login, registration, recovery, verification, and settings flows. Names can include generated suffixes.Normally 10 minutes for login and registration; some recovery links last up to 1 hour
avio_vpsAuthorizes a hosted verification portal session without exposing the one-time link token again.1 hour
avio_csrfBinds actions in the hosted verification portal to the browser that opened the session.1 hour
avio_envRemembers whether an approved developer console is displaying Test or Live resources. It cannot grant Live access.1 year

Authentication and hosted-verification session cookies are marked Secure and use SameSite protections. Sensitive session and OIDC cookies are HttpOnly. The avio_env display choice and avio_csrf browser token must be readable by the relevant client-side interface.

4. Other browser storage and provider cookies

The registration interface may use session storage to carry an email and a recent legal-acceptance marker between phases of the same registration journey. It is removed when the browser session ends. A network protection provider may set a short-lived challenge or bot-control cookie when that protection is activated. Such a cookie is used for traffic integrity, not advertising.

5. Analytics and advertising

The audited Authvio account, identity-provider, and hosted-verification code does not install advertising pixels or general-purpose third-party analytics cookies. Infrastructure request logs may still contain IP address, user agent, route, response status, and timing as described in the Privacy Policy.

6. Your controls

You can inspect, block, or delete cookies in browser settings. Blocking the authentication, CSRF, OIDC, or hosted-verification cookies will prevent the related flow from working. Signing out removes or revokes the relevant Authvio session, while deleting all site data clears remaining browser state.

7. Changes and contact

We update this policy when browser-storage behavior changes. Send a question through the legal and privacy request form. Read this policy with the Privacy Policy.

Questions about this document?

Authvio is a brand of Bolrach Technologies Limited. Send a legal or privacy request through the encrypted support form.