Origin:
Request Cookie header (authoritative): Checking…
Browser-visible document.cookie (secondary, excludes HttpOnly cookies):
CHECKING: waiting for the request-header probe
A PASS proves the browser did not attach an NDOS better-auth session cookie to a request for this origin. It does not by itself prove the wider isolation design.