Without domain: .vibnai.com the cookie is scoped to vibnai.com only. Browsers don't send it to theia.vibnai.com, so ForwardAuth sees no token and redirects to login even when the user is already logged in. Co-authored-by: Cursor <cursoragent@cursor.com>