CBEG Cockpit
Read-only decision desk over the canonical authority store.
The key is sent once, over HTTPS, in the body of this same-origin request, and is
cleared from the field the moment a response arrives. It is never placed in the URL,
in storage, or in the session cookie. The session cookie is HttpOnly, Secure,
SameSite=Strict, and expires within eight hours.