* Same-site flag. (Prevent access from other domains.) * HTTP-only flag. (Prevent access from JavaScript in-page.) * Secure (HTTPS-only) flag. (Prevent disclosure of cookie contents over insecure channels.)