If supported, web application session cookies set the HttpOnly flag, Secure flag and the SameSite flag by default.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.