FerryDocs
ArchitectureSecurity model

The session cookie

After you sign in, a cookie proves who you are. The JavaScript of the page cannot read it.

Edit on GitHub
Browseremail + passwordServerferry.dbSHA-256 only

You sign in at /login with your email and your password.

1 / 4

A is the proof that one browser signed in. The browser keeps it in the .

PropertyEffect
HttpOnlyThe JavaScript of the dashboard cannot read the cookie.
SameSite=StrictThe browser sends the cookie only with requests from the same site.
SecureSet when you reach the dashboard over through a proxy.
The name ferry_session_7878The name ends with the port of the address that you use.

When a session ends

  • 30 days after its last use.
  • When you sign out.
  • When you change the password: the session of each other browser ends.

In the dashboard, Server → Account lists the sessions. There, you can sign each browser out.

On this page