I think you need a better security team :slight_smile: if they don’t understand what they are requesting - or did you mis-type something here?

Httponly is fundamental to security - https://owasp.org/www-community/HttpOnly - turning it off is a Bad idea.