I think you need a better security team if they don’t understand what they are requesting - or did you mis-type something here?
Httponly is fundamental to security - https://owasp.org/www-community/HttpOnly - turning it off is a Bad idea.