# Token Transport

This page explains where the package reads tokens from a request, where it writes new tokens, and which cookie attributes it sets.

## Read Order

| Value | First | Fallback |
|---|---|---|
| Access Token | `authorization: Bearer <token>` header | cookie `AccessTokenCookieKey` (default `access_token`) |
| Refresh ID | `X-Refresh-ID` header | cookie `RefreshTokenCookieKey` (default `refresh_id`) |
| Device ID | `X-Device-ID` header | `req.body.deviceId` |

Cookies are read from `req.cookies`, so mount `cookie-parser` first.

## Write Locations

| When | Writes |
|---|---|
| `CreateJWT()` | Access cookie, refresh cookie; return value `{ token, refresh_id }` |
| `VerifyJWT()` on refresh | Access cookie, refresh cookie, `X-New-Access-Token`, `X-New-Refresh-ID` |
| `RevokeJWT()` | Clears both cookies |

## Cookie Attributes

| Attribute | `isProd: true` | `isProd: false` |
|---|---|---|
| `httpOnly` | `true` | `true` |
| `secure` | `true` | `false` |
| `sameSite` | `none` | `lax` |
| `domain` | `config.domain` | `localhost` |
| `path` | `/` | `/` |
| Lifetime | Access: `accessTokenExpires`; refresh: `refreshTokenExpires` | Same |

Related: [Client Integration](/client-integration), [Configuration](/configuration)
