Authentication cookie
When you sign in, Horizon sets an HTTP-only session cookie named horizon_session. It allows the Control Plane to recognize your authenticated session without exposing the session value to browser JavaScript.
How it works
The cookie is sent only to the configured Horizon application context, uses a same-site policy, and is cleared when you log out. The server stores a hash of the session value rather than the raw cookie value.
Optional tracking
The current MVP does not intentionally add advertising or analytics cookies. No cookie-consent banner is displayed for the functional authentication cookie.