Pattern
Cookie Scope Mismatch
cookie-scope-mismatch
JWT/session cookies get stored but aren’t sent or readable across redirects and subdomains because cookie attributes (domain, SameSite/third-party rules, httpOnly access, framework write location) don’t match the client’s request context, breaking auth flows.