We’re currently storing tokens in localStorage, and would like to move to storing them in httpOnly cookies to improve security. As an optional stretch goal, you can implement CSRF tokens as well.