Marked as helpful by the asker
Your gut is right for most apps. localStorage is readable by any script on the page, so one XSS hole means stolen sessions. HttpOnly cookies are not. Supabase's @supabase/ssr and Auth.js both do cookies for you; use the default instead of inventing the storage layer.