all 3 of them.
that is the complete list. not the ones we think you care about, not the ones in a category we chose — every cookie this site is capable of setting.
sb-<project>-auth-tokenyour signed-in session
lasts: until you sign out
set only after you sign in. without it there is no way to stay signed in between pages.
__Host-inaff_admthe admin console lock
lasts: 30 minutes
only ever set for an admin who has just re-entered their password. it is signed, it is not readable by script, and it expires on its own.
__Host-inaff_cookiesa record that you were shown this list
lasts: a year
set when you dismiss the cookie notice. it holds a date and a digest of this list, nothing else — no id, nothing about you. it is signed, so it cannot be edited, and it is not readable by script. change this list and it stops matching, so you get asked again.
what is not here
no analytics cookie. no advertising identifier. no third-party anything. no pixel, no tag manager, no session replay. nothing on this site reports your visit to a company that is not us.
which is why there is nothing to switch off. every cookie above is strictly necessary for something you asked for — signing in, or administering — and that is the exemption every consent law is written around. the notice you saw is a record that you were told, not a request for permission we would carry on without.
your acknowledgement
nothing recorded on this browser. the notice will be showing at the bottom of the page.