ring

Johnny 2020-07-08T08:59:09.107100Z

Figured it out with the help of @lsenjov. :same-site in the cookie attributes was set to :strict , needed to be :lax to get the same cookie when redirecting back from the oauth authorisation.