httpx's cookie jar only auto-attaches Secure cookies to https:// requests. Switching the ASGITransport client fixture's base_url from http://test to https://test (no real socket is opened either way) makes it behave like a browser talking to the Cloudflare-Tunnel-terminated HTTPS edge in production, eliminating the need for manual client.cookies.set(...) re-injection workarounds in test_auth.py. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof