Ed in Park City LLC

Cookie Policy

This policy explains how ThisMCP uses cookies and similar browser storage.

Last updated June 12, 2026

How ThisMCP uses cookies

The service uses essential cookies and similar storage for sign-in, session continuity, security, CSRF protection, OAuth state validation, PKCE validation, OIDC nonce validation, and routing users through the Client Explorer OAuth flow.

These cookies are necessary for the service to work. Disabling or deleting them may prevent sign-in or authenticated gateway management features from functioning.

Cookie table

CookiePurposeCategoryDuration
thismcp.next-auth.session-token or __Secure-thismcp.next-auth.session-tokenMaintains the authenticated session and Client Explorer OAuth session state for the control plane.Essential authenticationUp to 30 days.
thismcp.next-auth.callback-url or __Secure-thismcp.next-auth.callback-urlStores the destination used to return a user to the intended page after sign-in.Essential authentication routingBrowser session.
thismcp.next-auth.csrf-token or __Host-thismcp.next-auth.csrf-tokenProtects authentication requests against cross-site request forgery.Essential securityBrowser session.
thismcp.next-auth.pkce.code_verifier or __Secure-thismcp.next-auth.pkce.code_verifierSupports OAuth PKCE validation during Client Explorer sign-in.Essential OAuth securityAbout 15 minutes.
thismcp.next-auth.state or __Secure-thismcp.next-auth.stateValidates OAuth state during Client Explorer sign-in.Essential OAuth securityAbout 15 minutes.
thismcp.next-auth.nonce or __Secure-thismcp.next-auth.nonceValidates OIDC nonce values during Client Explorer sign-in.Essential OAuth securityBrowser session.

Analytics and telemetry

ThisMCP is not designed to use advertising cookies. The current product telemetry sends same-origin analytics requests from the browser to ThisMCP and then to Client Explorer analytics using the authenticated session; it does not set a separate advertising or cross-site tracking cookie.

Page analytics may include page URL, document title, referrer, pathname, timestamp, and group ID when available. Server-side action analytics may include action names and scalar non-secret properties. Analytics events should not include secrets, tokens, private API keys, recipient emails, upstream headers, environment variables, commands, tool arguments, tool results, message bodies, provider redirect URLs, or third-party session identifiers.

Third-party cookies and storage

Client Explorer, identity providers, upstream MCP providers, model providers, hosting providers, organization-managed browsers, and other third-party services may set or use their own cookies or similar technologies under their own notices and policies.

When you follow links to third-party services or configure upstream providers, review those providers' cookie and privacy notices.

Managing cookies

You can manage cookies through your browser settings. Browser-level blocking or deletion may sign you out, interrupt OAuth flows, or prevent authenticated gateway management features from working.

If ThisMCP adds non-essential cookies or similar browser storage in production, this policy should be updated and any required consent or choice mechanism should be provided before those technologies are used.