Last updated 9 October 2026.
1. What are cookies and storage technologies?
Cookies are small text files stored on your device when you visit a website. They help the site remember information about your visit, such as your sign-in state. Alongside HTTP cookies, web applications may use browser local storage and session storage for interface preferences. The dashboard keeps its session in HttpOnly cookies, not in browser storage, so scripts running on the page cannot read it.
First-party cookies belong to the site you are visiting. Third-party cookies belong to another domain, such as an embedded service. A service provider may also set cookies on our domain. Section 5 describes these services.
2. Categories of cookies we use
Strictly necessary. Required for sign-in and security in the dashboard and on MAGDOX's sign-in service: the session, protection of the sign-in redirect, the two-step verification step and the email confirmation step. Blocking them prevents sign-in; your browser still controls whether to accept them.
Functional. Code Security remembers whether the navigation is collapsed; FDIE also stores interface and MFA-reminder preferences. This website's own code stores no preferences.
Analytics. With your permission, this website, the Code Security dashboard and FDIE use PostHog to understand which pages and controls are used. PostHog keeps a random identifier in browser local storage, not in a cookie, and nothing is stored until you allow analytics. You can change the choice at any time from Cookie Settings in the website footer, from Settings in the dashboard or from Settings, Data & Privacy in FDIE.
We do not use any cookie or storage mechanism for advertising or cross-site retargeting.
3. Cookies and storage keys we use
These keys are set by MAGDOX in the MAGDOX Code Security dashboard only. Over HTTPS, cookie names carry the __Host- prefix, which makes the browser refuse them unless they are Secure, scoped to the dashboard's own host and not shared with other subdomains.
| Name and storage | Purpose | Duration | Category |
|---|---|---|---|
| __Host-magdox_session (cookie) | Keeps you signed in; HttpOnly, Secure, SameSite=Lax | Ends after 30 minutes of inactivity and at most 12 hours after sign-in | Strictly necessary |
| __Host-magdox_oauth (cookie) | Protects the sign-in redirect against forgery | 10 minutes | Strictly necessary |
| __Host-magdox_mfa (cookie) | Holds a sign-in between its first step and the two-step verification code | 5 minutes | Strictly necessary |
| __Host-magdox_verify (cookie) | Holds a GitHub sign-in while you enter the code we emailed to confirm your address | 10 minutes | Strictly necessary |
| __Host-magdox_tile (cookie) | Allows one retry when you open MAGDOX from your organisation's identity provider portal, so a failing sign-in cannot repeat in a loop | 2 minutes | Strictly necessary |
| __Host-magdox_return (cookie) | Returns you to the CLI device-approval page after sign-in; holds a fixed word, never a URL | 10 minutes | Strictly necessary |
| __Host-magdox_pkce (cookie) | Holds the one-time code verifier that completes a sign-in redirect | 10 minutes | Strictly necessary |
| magdox:last-request (local storage) | The time of your last request, shared between tabs, so that an idle session signs out on time | Until browser storage is cleared | Strictly necessary |
| magdox.nav.collapsed (local storage) | Remembers whether the navigation is collapsed | Until browser storage is cleared | Functional |
| magdox-analytics (local storage) | Remembers your analytics choice so you are asked only once | Until browser storage is cleared | Functional |
| magdox.maintenance.dismissed (local storage) | Remembers which maintenance notices you closed | Until browser storage is cleared | Functional |
| magdox.plan-change (session storage) | Tells the Plans page that you chose to change plan; removed when the page reads it | One page load | Functional |
| magdox:stale-build-reload (session storage) | The time of one automatic reload after a new release, so a page reloads at most once a minute | Until the tab is closed | Functional |
| ph_<project>_posthog (local storage) | PostHog's random identifier and visit state; set only after you allow analytics | Deleted when you turn analytics off, otherwise until browser storage is cleared | Analytics |
| __ph_opt_in_out_<project> (local storage) | PostHog's copy of your analytics choice; holds no identifier | Until browser storage is cleared | Analytics |
| ph_<project>_… (session storage) | Visit state for the current tab, such as a random tab identifier; set only after you allow analytics | Until the tab is closed | Analytics |
Cross-site request forgery protection uses a token held with your server-side session and sent in a request header, not a separate cookie. Local development uses the same names without the __Host- prefix. Code Security browser storage never holds a session credential. FDIE's short-lived sign-in handoff is separately described below.
MAGDOX's sign-in service sets its own strictly necessary cookies on the sign-in domain while you sign in. They are scoped to that service, are Secure, and are not used for any other purpose.
| Name | Purpose | Duration | Category |
|---|---|---|---|
| AUTH_SESSION_ID | Ties the steps of one sign-in together; HttpOnly | Until the browser closes | Strictly necessary |
| KC_AUTH_SESSION_HASH | Checks that the sign-in steps come from the same browser | 60 seconds | Strictly necessary |
| KC_RESTART | Lets an interrupted sign-in start again; HttpOnly | Until the browser closes | Strictly necessary |
| KEYCLOAK_IDENTITY and KEYCLOAK_SESSION | Record the completed sign-in on the sign-in service; they are never used to sign anyone in again without returning to the chosen sign-in method | Until the browser closes, and at most 12 hours | Strictly necessary |
| Name / storage | Purpose | Duration | Category |
|---|---|---|---|
| __Host-fdie_session / cookie | Production signed-in session; HttpOnly and Secure | 30-minute inactivity timeout, refreshed during authenticated use, and at most 24 hours after sign-in | Strictly necessary |
| csrf_token / cookie | FDIE cross-site request forgery protection | Up to 24 hours, renewed with the session | Strictly necessary |
| fdie_mfa_handoff, fdie_mfa_methods, fdie_mfa_setup_handoff / cookies | Pending MFA or setup step; HttpOnly | 5 minutes, removed after use | Strictly necessary |
| fdie_reactivation_handoff / cookie | Pending reactivation step; HttpOnly | 5 minutes | Strictly necessary |
| fdie_sso_… / cookies | Bind an SSO callback to its initiating browser; HttpOnly | 5 minutes | Strictly necessary |
| fdie_just_verified / cookie | Email-verification confirmation | 10 minutes | Functional |
| fdie-login-handoff / sessionStorage | Pending sign-in/MFA/reactivation handoff without placing it in a URL; not the signed-in session | Removed when consumed, at most the tab session | Strictly necessary |
| fdie_sidebar_collapsed, fdie_mfa_reminder_dismissed_…, fdie_maintenance_dismissed_… / localStorage | Navigation, reminder and maintenance-notice preferences | Until cleared | Functional |
| fdie:stale-build-reload, fdie-font-repair / sessionStorage | The time of one automatic reload after a new release, and a one-time repair of fonts cached by an earlier release | Until the tab is closed | Functional |
| fdie_analytics_choice / localStorage | Remembers your analytics choice so you are asked only once | Until cleared | Functional |
| ph_<project>_posthog, __ph_opt_in_out_<project> / localStorage; ph_<project>_… / sessionStorage | PostHog's random identifier, its copy of your choice and visit state; the identifier and visit state are set only after you allow analytics | The identifier is deleted when you turn analytics off; otherwise until cleared or the tab is closed | Analytics |
FDIE development configurations can use fdie_session without the production prefix. The sign-in provider may use its own cookies on its own domain. The retired FDIE marketing site's analytics or newsletter relay are not carried into this website: current magdox.io behaviour governs this notice.
This website sets no cookies of its own. In local storage it keeps your analytics choice (magdox-analytics) and, only if you allow analytics, the PostHog keys listed in the dashboard table above, with the same purposes and durations. If a page fails to load because a newer version of the site was published, session storage keeps the time of one automatic reload (magdox:stale-build-reload) so the page reloads at most once a minute. Embedded services and Cloudflare security features may set cookies; see Section 5.
4. Managing your cookie preferences
This website asks before starting optional analytics and keeps the answer in browser storage; choose Cookie Settings in the footer to change it. In the Code Security dashboard the same choice is under Settings, Profile, Product analytics, and in FDIE under Settings, Data & Privacy, Product analytics. Turning analytics off stops sending at once and clears PostHog's identifier on that browser. You can block third-party storage in your browser, and email us directly instead of using the booking calendar. Dashboard session cookies are needed to sign in; blocking them prevents sign-in. The navigation preference can be cleared through your browser's site-data settings.
Most browsers let you block or delete cookies and site storage in their settings, though doing so may affect site functionality. Consult your browser's help pages (Chrome, Firefox, Safari or Edge).
5. Third-party cookies and embedded content
The booking calendar is provided by Cal.com. Its embed script and calendar load on the Contact page, or when you select Schedule a Call elsewhere on the website. Cal.com and its security providers may use cookies or browser storage in that context. Booking details and relevant technical data are processed under Cal.com's privacy notice, available at https://cal.com/privacy. A direct booking link opens Cal.com's own site; email remains an alternative to using the calendar.
The contact and newsletter forms post your details to this website, which files them in MAGDOX CRM (self-hosted on Oracle Cloud in India). MAGDOX sets no cookies for these forms. If Cloudflare Turnstile is enabled on them, it may use its own cookies or storage to tell people from automated submissions, under Cloudflare's privacy notice.
Checkout and the billing portal for plans bought online run on Dodo Payments' own pages, which use their own cookies under Dodo Payments' notices. MAGDOX sets no billing cookies.
Google and GitHub, if you choose to sign in with them, and your organisation's single sign-on provider may use their own cookies on their own sign-in pages.
The selected product profile uses AWS CloudFront and AWS WAF for delivery and protection. This does not move the separately operated marketing website or automatically remove existing Cloudflare integrations. Where Cloudflare remains enabled, security cookies such as __cf_bm or cf_clearance may be set, including without an interactive challenge. AWS delivery does not by itself add an advertising cookie; any separately enabled challenge/token feature must be reflected in this inventory before use.
Sentry monitoring sets no cookies and never records sessions on screen. This website sends filtered error events only; the Code Security dashboard also sends page-load and navigation timings with the page path. FDIE diagnostics use the separate product configuration described in the Privacy Policy; that does not add advertising cookies to this website. Where you allow analytics, PostHog receives the events described in the Privacy Policy, never session recordings, page text or form contents. We do not deploy advertising or retargeting trackers.
6. Changes to this policy
We may update this Cookie Policy as our use of cookies and storage changes. The last updated date at the top of this page reflects the most recent revision. See also our Privacy Policy.
7. Contact
Questions about this Cookie Policy can be sent to privacy@magdox.io or through our Contact page, or by post to MAGDOX Private Limited, St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India.