Legal

Cookie Policy

What cookies and browser storage magdox.io, Code Security and FDIE use, with a separate inventory for each application and its sign-in flow.

Last updated 9 October 2026.

1. What are cookies and storage technologies?

Cookies are small text files stored on your device when you visit a website. They help the site remember information about your visit, such as your sign-in state. Alongside HTTP cookies, web applications may use browser local storage and session storage for interface preferences. The dashboard keeps its session in HttpOnly cookies, not in browser storage, so scripts running on the page cannot read it.

First-party cookies belong to the site you are visiting. Third-party cookies belong to another domain, such as an embedded service. A service provider may also set cookies on our domain. Section 5 describes these services.

2. Categories of cookies we use

Strictly necessary. Required for sign-in and security in the dashboard and on MAGDOX's sign-in service: the session, protection of the sign-in redirect, the two-step verification step and the email confirmation step. Blocking them prevents sign-in; your browser still controls whether to accept them.

Functional. Code Security remembers whether the navigation is collapsed; FDIE also stores interface and MFA-reminder preferences. This website's own code stores no preferences.

Analytics. With your permission, this website, the Code Security dashboard and FDIE use PostHog to understand which pages and controls are used. PostHog keeps a random identifier in browser local storage, not in a cookie, and nothing is stored until you allow analytics. You can change the choice at any time from Cookie Settings in the website footer, from Settings in the dashboard or from Settings, Data & Privacy in FDIE.

We do not use any cookie or storage mechanism for advertising or cross-site retargeting.

3. Cookies and storage keys we use

These keys are set by MAGDOX in the MAGDOX Code Security dashboard only. Over HTTPS, cookie names carry the __Host- prefix, which makes the browser refuse them unless they are Secure, scoped to the dashboard's own host and not shared with other subdomains.

Dashboard cookies and storage
Name and storagePurposeDurationCategory
__Host-magdox_session (cookie)Keeps you signed in; HttpOnly, Secure, SameSite=LaxEnds after 30 minutes of inactivity and at most 12 hours after sign-inStrictly necessary
__Host-magdox_oauth (cookie)Protects the sign-in redirect against forgery10 minutesStrictly necessary
__Host-magdox_mfa (cookie)Holds a sign-in between its first step and the two-step verification code5 minutesStrictly necessary
__Host-magdox_verify (cookie)Holds a GitHub sign-in while you enter the code we emailed to confirm your address10 minutesStrictly necessary
__Host-magdox_tile (cookie)Allows one retry when you open MAGDOX from your organisation's identity provider portal, so a failing sign-in cannot repeat in a loop2 minutesStrictly necessary
__Host-magdox_return (cookie)Returns you to the CLI device-approval page after sign-in; holds a fixed word, never a URL10 minutesStrictly necessary
__Host-magdox_pkce (cookie)Holds the one-time code verifier that completes a sign-in redirect10 minutesStrictly necessary
magdox:last-request (local storage)The time of your last request, shared between tabs, so that an idle session signs out on timeUntil browser storage is clearedStrictly necessary
magdox.nav.collapsed (local storage)Remembers whether the navigation is collapsedUntil browser storage is clearedFunctional
magdox-analytics (local storage)Remembers your analytics choice so you are asked only onceUntil browser storage is clearedFunctional
magdox.maintenance.dismissed (local storage)Remembers which maintenance notices you closedUntil browser storage is clearedFunctional
magdox.plan-change (session storage)Tells the Plans page that you chose to change plan; removed when the page reads itOne page loadFunctional
magdox:stale-build-reload (session storage)The time of one automatic reload after a new release, so a page reloads at most once a minuteUntil the tab is closedFunctional
ph_<project>_posthog (local storage)PostHog's random identifier and visit state; set only after you allow analyticsDeleted when you turn analytics off, otherwise until browser storage is clearedAnalytics
__ph_opt_in_out_<project> (local storage)PostHog's copy of your analytics choice; holds no identifierUntil browser storage is clearedAnalytics
ph_<project>_… (session storage)Visit state for the current tab, such as a random tab identifier; set only after you allow analyticsUntil the tab is closedAnalytics

Cross-site request forgery protection uses a token held with your server-side session and sent in a request header, not a separate cookie. Local development uses the same names without the __Host- prefix. Code Security browser storage never holds a session credential. FDIE's short-lived sign-in handoff is separately described below.

MAGDOX's sign-in service sets its own strictly necessary cookies on the sign-in domain while you sign in. They are scoped to that service, are Secure, and are not used for any other purpose.

Sign-in service cookies
NamePurposeDurationCategory
AUTH_SESSION_IDTies the steps of one sign-in together; HttpOnlyUntil the browser closesStrictly necessary
KC_AUTH_SESSION_HASHChecks that the sign-in steps come from the same browser60 secondsStrictly necessary
KC_RESTARTLets an interrupted sign-in start again; HttpOnlyUntil the browser closesStrictly necessary
KEYCLOAK_IDENTITY and KEYCLOAK_SESSIONRecord the completed sign-in on the sign-in service; they are never used to sign anyone in again without returning to the chosen sign-in methodUntil the browser closes, and at most 12 hoursStrictly necessary
FDIE cookies and browser storage
Name / storagePurposeDurationCategory
__Host-fdie_session / cookieProduction signed-in session; HttpOnly and Secure30-minute inactivity timeout, refreshed during authenticated use, and at most 24 hours after sign-inStrictly necessary
csrf_token / cookieFDIE cross-site request forgery protectionUp to 24 hours, renewed with the sessionStrictly necessary
fdie_mfa_handoff, fdie_mfa_methods, fdie_mfa_setup_handoff / cookiesPending MFA or setup step; HttpOnly5 minutes, removed after useStrictly necessary
fdie_reactivation_handoff / cookiePending reactivation step; HttpOnly5 minutesStrictly necessary
fdie_sso_… / cookiesBind an SSO callback to its initiating browser; HttpOnly5 minutesStrictly necessary
fdie_just_verified / cookieEmail-verification confirmation10 minutesFunctional
fdie-login-handoff / sessionStoragePending sign-in/MFA/reactivation handoff without placing it in a URL; not the signed-in sessionRemoved when consumed, at most the tab sessionStrictly necessary
fdie_sidebar_collapsed, fdie_mfa_reminder_dismissed_…, fdie_maintenance_dismissed_… / localStorageNavigation, reminder and maintenance-notice preferencesUntil clearedFunctional
fdie:stale-build-reload, fdie-font-repair / sessionStorageThe time of one automatic reload after a new release, and a one-time repair of fonts cached by an earlier releaseUntil the tab is closedFunctional
fdie_analytics_choice / localStorageRemembers your analytics choice so you are asked only onceUntil clearedFunctional
ph_<project>_posthog, __ph_opt_in_out_<project> / localStorage; ph_<project>_… / sessionStoragePostHog's random identifier, its copy of your choice and visit state; the identifier and visit state are set only after you allow analyticsThe identifier is deleted when you turn analytics off; otherwise until cleared or the tab is closedAnalytics

FDIE development configurations can use fdie_session without the production prefix. The sign-in provider may use its own cookies on its own domain. The retired FDIE marketing site's analytics or newsletter relay are not carried into this website: current magdox.io behaviour governs this notice.

This website sets no cookies of its own. In local storage it keeps your analytics choice (magdox-analytics) and, only if you allow analytics, the PostHog keys listed in the dashboard table above, with the same purposes and durations. If a page fails to load because a newer version of the site was published, session storage keeps the time of one automatic reload (magdox:stale-build-reload) so the page reloads at most once a minute. Embedded services and Cloudflare security features may set cookies; see Section 5.

4. Managing your cookie preferences

This website asks before starting optional analytics and keeps the answer in browser storage; choose Cookie Settings in the footer to change it. In the Code Security dashboard the same choice is under Settings, Profile, Product analytics, and in FDIE under Settings, Data & Privacy, Product analytics. Turning analytics off stops sending at once and clears PostHog's identifier on that browser. You can block third-party storage in your browser, and email us directly instead of using the booking calendar. Dashboard session cookies are needed to sign in; blocking them prevents sign-in. The navigation preference can be cleared through your browser's site-data settings.

Most browsers let you block or delete cookies and site storage in their settings, though doing so may affect site functionality. Consult your browser's help pages (Chrome, Firefox, Safari or Edge).

5. Third-party cookies and embedded content

The booking calendar is provided by Cal.com. Its embed script and calendar load on the Contact page, or when you select Schedule a Call elsewhere on the website. Cal.com and its security providers may use cookies or browser storage in that context. Booking details and relevant technical data are processed under Cal.com's privacy notice, available at https://cal.com/privacy. A direct booking link opens Cal.com's own site; email remains an alternative to using the calendar.

The contact and newsletter forms post your details to this website, which files them in MAGDOX CRM (self-hosted on Oracle Cloud in India). MAGDOX sets no cookies for these forms. If Cloudflare Turnstile is enabled on them, it may use its own cookies or storage to tell people from automated submissions, under Cloudflare's privacy notice.

Checkout and the billing portal for plans bought online run on Dodo Payments' own pages, which use their own cookies under Dodo Payments' notices. MAGDOX sets no billing cookies.

Google and GitHub, if you choose to sign in with them, and your organisation's single sign-on provider may use their own cookies on their own sign-in pages.

The selected product profile uses AWS CloudFront and AWS WAF for delivery and protection. This does not move the separately operated marketing website or automatically remove existing Cloudflare integrations. Where Cloudflare remains enabled, security cookies such as __cf_bm or cf_clearance may be set, including without an interactive challenge. AWS delivery does not by itself add an advertising cookie; any separately enabled challenge/token feature must be reflected in this inventory before use.

Sentry monitoring sets no cookies and never records sessions on screen. This website sends filtered error events only; the Code Security dashboard also sends page-load and navigation timings with the page path. FDIE diagnostics use the separate product configuration described in the Privacy Policy; that does not add advertising cookies to this website. Where you allow analytics, PostHog receives the events described in the Privacy Policy, never session recordings, page text or form contents. We do not deploy advertising or retargeting trackers.

6. Changes to this policy

We may update this Cookie Policy as our use of cookies and storage changes. The last updated date at the top of this page reflects the most recent revision. See also our Privacy Policy.

7. Contact

Questions about this Cookie Policy can be sent to privacy@magdox.io or through our Contact page, or by post to MAGDOX Private Limited, St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India.