I don't know what XHR is, nor anything about CDNs. The cookie is issued on a request for a protected page. By definition if you get a bunch you don't have the application designed appropriately. There should be a single top level resource requiring authentication covering everything else, not a lot of embedded content inside an unprotected page. -- Scott