Checks

__Secure- cookie is invalid

A cookie name starts with __Secure- but the Secure attribute is missing.

Why it matters

Browsers reject that cookie.

What to do

Add Secure, or drop the __Secure- prefix.

Reference

Cookie attributes such as Secure, HttpOnly, and SameSite protect session tokens in browsers.

OWASP Session Management Cheat Sheet