We released a new version of Ory CLI as well as a new documentation on “Ory’s Security Model” (
https://www.ory.sh/docs/security-model ). We hope it helps in understanding how Ory Sessions and Ory Tokens work and what is needed to get CSRF & Cookies right! We appreciate any feedback :)