Guest session
Check Detail

costco.com · HEADER

Incomplete Grade F
34.6%
Hostname costco.com
Check name HEADER
last run 10/03/2026 21:10
Result
Incomplete Grade B 78.2%

Result Detail

HEADER
Alerts
  • Strict-Transport-Security: HSTS active but consider preload
  • X-Content-Type-Options: Header missing
  • X-Frame-Options: Header missing
  • Referrer-Policy: Header missing
  • Permissions-Policy: Permissions-Policy missing
  • Cross-Origin-Opener-Policy: Header missing
  • Cross-Origin-Embedder-Policy: Header missing
  • Cross-Origin-Resource-Policy: Header missing
  • Expect-CT: Expect-CT missing
  • X-Permitted-Cross-Domain-Policies: Header missing
  • Access-Control-Allow-Origin: Access-Control-Allow-Origin missing
  • Server: Sensitive header exposed
  • Origin-Agent-Cluster: Header missing
Normalized headers
content-security-policy default-src 'self' https://*.queue-it.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscentre.ca/ https://*.costcobusinesscenter.ca/ https://*.costco-static.com/ https://display.ugc.bazaarvoice.com/ https://api.bazaarvoice.com/; script-src 'self' https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.cdn-path.com/ https://h.costco.com/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com https://*.costcobusinesscenter.ca/ https://cdn.intake-lr.com/ https://cdn.cookielaw.org/ https://*.criteo.com/ http://*.criteo.com/ https://assets.adobedtm.com/ https://s.go-mpulse.net/ https://transcend-cdn.com/ https://apps.bazaarvoice.com/ https://display.ugc.bazaarvoice.com/ https://mobilecontent.costco.com/ https://mobilecontent-qa.costco.com/ https://*.pxlecdn.com https://*.pixlee.com https://*.pixlee.co 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://cdn.fonts.net/ 'unsafe-inline' https://transcend-cdn.com/ https://consent.costco.com/ https://consent.costco.ca/ https://consent.costco.com https://display.ugc.bazaarvoice.com/; img-src 'self' https://*.costcobusinessdelivery.com https://*.tiles.virtualearth.net/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcotravel.com/ https://*.costcotravel.ca/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://cdn.cookielaw.org/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://display.ugc.bazaarvoice.com https://retailmedia-static.azureedge.net https://retailmedia-static.azureedge.net/ https://network-a.bazaarvoice.com https://network-stg-a.bazaarvoice.com https://retailmedia-static.criteo.com/ blob: data:; media-src 'self' https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://*.criteo.net/ https://retailmedia-static.criteo.com/ https://*.criteo.net; font-src 'self' https://cdn.bfldr.com/ https://*.costco-static.com/ https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self' about:; form-action 'self' https://*.cardinalcommerce.com https://www.cdn-path.com/ https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://r.intake-lr.com/ https://*.akstat.io https://*.opinionlab.com; frame-src https://*.cardinalcommerce.com https://www.cdn-path.com/ https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://*.costcobusinessdelivery.com https://*.costcobusinesscentre.ca/ https://*.ct-costco.com https://costco.demdex.net/ https://costco.centah.com/ https://consent-sync.costco.com/ https://consent-sync.costco.ca/ https://*.criteo.com/ http://*.criteo.com https://*.pixlee.com https://*.pixlee.co https://*.costco.com/ https://*.costco.ca/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://h.costco.com/ https://cdn.bfldr.com/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://gdx-api.costco.com https://gdx-npd.np.api.cc-costco.com https://api-tst.np.gdx.cc-costco.com https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://spatial.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscenter.ca/ https://*.costcobusinesscentre.ca/ https://*.costco.ca/ https://*.costco.com/ https://*.costco-static.com/ https://*.ct-costco.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/ https://costco.demdex.net/ https://dpm.demdex.net/ https://costco.tt.omtrdc.net/ https://*.criteo.com/ http://*.criteo.com/ https://*.criteo.net/ https://cm.everesttech.net/ https://r.intake-lr.com/ https://*.contentstack.com/ https://assets.adobedtm.com/ https://dcs.adobedc.net/ https://*.akstat.io https://*.go-mpulse.net/ https://*.akamaihd.net https://adobedc.demdex.net/ https://sync-transcend-cdn.com https://transcend-cdn.com/ https://telemetry.transcend.io/ https://telemetry.us.transcend.io/ https://privacyportal.onetrust.com/ https://consent.us.transcend.io/ https://api.bazaarvoice.com/ https://stg.api.bazaarvoice.com/; child-src 'self' blob: data:; upgrade-insecure-requests;
x-build-reference 1.22.3-22734697192
x-build-tag prd-usbc-release-v1.22.3
x-next-i18n-router-locale en-us
x-middleware-rewrite /en-us
x-nextjs-cache HIT
etag "d1pz6eidr723spo"
content-type text/html; charset=utf-8
x-envoy-upstream-service-time 131
server istio-envoy
x-costco-gdx-deployment blue
x-costco-gdx-backend external-web-backend
expires Tue, 10 Mar 2026 20:10:30 GMT
cache-control max-age=0, no-cache, no-store
pragma no-cache
date Tue, 10 Mar 2026 20:10:30 GMT
set-cookie akavpau_zezxapz5yf=1773173730~id=a7ef94cd70880256732654e9e330ae45; Domain=www.costco.com; Path=/; Secure; SameSite=None; akaas_AS01=2147483647~rv=87~id=8d51425b09913196ebd01f5db5ffeb62; path=/; Secure; SameSite=None; _abck=F639C64530D4600E9D6DAB2335799CDA~-1~YAAQf1ATAnp8fNecAQAARFlf2Q/MZkLP17JBN/UE8rXmQl6Jobusi+S0M3ajzrhgG5Q1s7nJFrs70pcfXdV0+woRZQpEKUYPAEWH0GSpf/2d+RDof2aofJVf4Dd2VHRHXd6QOqG+UTyARbVnzSQpFr/hTsjuSk1Z+0G8xhgzSBk6WuMX7naaHT0epCAStVyP0wbqfqWPL1q5bVB3rOHb9Hz5BftUg0Mspoc0qoLra1v82FmL87o8x4GS6BA4ypjHMyGsmUJ1I3mQWZ3dcJF1CG/7gBB54F02LwYhLq/730cu0f8tpmB/9dxcTEyY3BOWG6xU4749BqHMhD/nnsTTfv5nKFmPEP+ufsoHm29j/VKrStFW+xsQ2GmDGnukthEh2OumuX7eT/tdiy726BnHANAGVWw5xAfgVo1K4GZxRACeB44CUfQyeRWLV8ErrHQvlNaBKD/aMQk=~-1~-1~-1~-1~-1; Domain=.costco.com; Path=/; Expires=Wed, 10 Mar 2027 20:10:30 GMT; Max-Age=31536000; Secure; bm_sz=009AECE71F1CD987390315E6BCF6925C~YAAQf1ATAnt8fNecAQAARFlf2R8pVYoBWNUE8nW4+iCicGeIsVnzbADtaVr1f/4XTUD+0QMXbwqbmW6Roz0Bq29CWe0ThELCkaJkZuutROAQEShmdS+KOrJN5CVB28RWu4u2mjd+sc7hpAnNGO/RxtiKLwPaLIz7OYFaOsmCgukVgwQ0gd0laPDcqT1zfswoD5vPcqEk4s8LBbstn1Xp3ra7Fnppe786VcN4acE/IvvACJlVq0pzDuVlvj3r/fda5bkrHqXpP6ZltGfIN2dNzw4NQafrkwg4lZ3aNTC5wHCgeoPZSrR9MeJWFUiH72F06KofwaTpRYNL+u1wyqPKu9QAdIk+v1nmWLFqnpJWpRHXsNpvoA==~3356216~3224641; Domain=.costco.com; Path=/; Expires=Wed, 11 Mar 2026 00:10:30 GMT; Max-Age=14400
strict-transport-security max-age=31536000;includeSubDomains
server-timing ak_p; desc="1773173430506_34820223_10955312_3413_23849_33_27_15";dur=1
Transport
Check name Status Actual Expected Detail Severity Recommendation
Strict-Transport-Security ⚠️ Warning max-age=31536000;includeSubDomains max-age>=15768000; includeSubDomains; preload HSTS active but consider preload Critical Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Expect-CT ❌ Missing enforce; max-age>=86400 Expect-CT missing Medium Expect-CT: enforce, max-age=86400, report-uri="https://report.example.com"
Content Security
Check name Status Actual Expected Detail Severity Recommendation
Content-Security-Policy ✅ Passed default-src 'self' https://*.queue-it.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscentre.ca/ https://*.costcobusinesscenter.ca/ https://*.costco-static.com/ https://display.ugc.bazaarvoice.com/ https://api.bazaarvoice.com/; script-src 'self' https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.cdn-path.com/ https://h.costco.com/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com https://*.costcobusinesscenter.ca/ https://cdn.intake-lr.com/ https://cdn.cookielaw.org/ https://*.criteo.com/ http://*.criteo.com/ https://assets.adobedtm.com/ https://s.go-mpulse.net/ https://transcend-cdn.com/ https://apps.bazaarvoice.com/ https://display.ugc.bazaarvoice.com/ https://mobilecontent.costco.com/ https://mobilecontent-qa.costco.com/ https://*.pxlecdn.com https://*.pixlee.com https://*.pixlee.co 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://cdn.fonts.net/ 'unsafe-inline' https://transcend-cdn.com/ https://consent.costco.com/ https://consent.costco.ca/ https://consent.costco.com https://display.ugc.bazaarvoice.com/; img-src 'self' https://*.costcobusinessdelivery.com https://*.tiles.virtualearth.net/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcotravel.com/ https://*.costcotravel.ca/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://cdn.cookielaw.org/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://display.ugc.bazaarvoice.com https://retailmedia-static.azureedge.net https://retailmedia-static.azureedge.net/ https://network-a.bazaarvoice.com https://network-stg-a.bazaarvoice.com https://retailmedia-static.criteo.com/ blob: data:; media-src 'self' https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://*.criteo.net/ https://retailmedia-static.criteo.com/ https://*.criteo.net; font-src 'self' https://cdn.bfldr.com/ https://*.costco-static.com/ https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self' about:; form-action 'self' https://*.cardinalcommerce.com https://www.cdn-path.com/ https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://r.intake-lr.com/ https://*.akstat.io https://*.opinionlab.com; frame-src https://*.cardinalcommerce.com https://www.cdn-path.com/ https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://*.costcobusinessdelivery.com https://*.costcobusinesscentre.ca/ https://*.ct-costco.com https://costco.demdex.net/ https://costco.centah.com/ https://consent-sync.costco.com/ https://consent-sync.costco.ca/ https://*.criteo.com/ http://*.criteo.com https://*.pixlee.com https://*.pixlee.co https://*.costco.com/ https://*.costco.ca/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://h.costco.com/ https://cdn.bfldr.com/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://gdx-api.costco.com https://gdx-npd.np.api.cc-costco.com https://api-tst.np.gdx.cc-costco.com https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://spatial.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscenter.ca/ https://*.costcobusinesscentre.ca/ https://*.costco.ca/ https://*.costco.com/ https://*.costco-static.com/ https://*.ct-costco.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/ https://costco.demdex.net/ https://dpm.demdex.net/ https://costco.tt.omtrdc.net/ https://*.criteo.com/ http://*.criteo.com/ https://*.criteo.net/ https://cm.everesttech.net/ https://r.intake-lr.com/ https://*.contentstack.com/ https://assets.adobedtm.com/ https://dcs.adobedc.net/ https://*.akstat.io https://*.go-mpulse.net/ https://*.akamaihd.net https://adobedc.demdex.net/ https://sync-transcend-cdn.com https://transcend-cdn.com/ https://telemetry.transcend.io/ https://telemetry.us.transcend.io/ https://privacyportal.onetrust.com/ https://consent.us.transcend.io/ https://api.bazaarvoice.com/ https://stg.api.bazaarvoice.com/; child-src 'self' blob: data:; upgrade-insecure-requests; default-src 'self'; frame-ancestors 'none' default-src 'self'; frame-ancestors 'none' Critical Content-Security-Policy: default-src 'self'; frame-ancestors 'none'
MIME
Check name Status Actual Expected Detail Severity Recommendation
X-Content-Type-Options ❌ Missing nosniff Header missing High X-Content-Type-Options: nosniff
Framing
Check name Status Actual Expected Detail Severity Recommendation
X-Frame-Options ❌ Missing DENY or SAMEORIGIN Header missing High X-Frame-Options: DENY
Privacy
Check name Status Actual Expected Detail Severity Recommendation
Referrer-Policy ❌ Missing strict-origin-when-cross-origin / same-origin Header missing Medium Referrer-Policy: strict-origin-when-cross-origin
Browser Features
Check name Status Actual Expected Detail Severity Recommendation
Permissions-Policy ❌ Missing camera=(); geolocation=(); microphone=() Permissions-Policy missing Medium Permissions-Policy: camera=(), geolocation=(), microphone=()
Cross-Origin
Check name Status Actual Expected Detail Severity Recommendation
Cross-Origin-Opener-Policy ❌ Missing same-origin Header missing High Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Embedder-Policy ❌ Missing require-corp Header missing High Cross-Origin-Embedder-Policy: require-corp
Cross-Origin-Resource-Policy ❌ Missing same-origin Header missing Medium Cross-Origin-Resource-Policy: same-origin
Origin-Agent-Cluster ❌ Missing ?1 Header missing Low Origin-Agent-Cluster: ?1
Caching
Check name Status Actual Expected Detail Severity Recommendation
Cache-Control ✅ Passed max-age=0, no-cache, no-store no-store, private, max-age=0 no-store, private, max-age=0 High Cache-Control: no-store, private, max-age=0
Legacy
Check name Status Actual Expected Detail Severity Recommendation
X-Permitted-Cross-Domain-Policies ❌ Missing none Header missing Low X-Permitted-Cross-Domain-Policies: none
CORS
Check name Status Actual Expected Detail Severity Recommendation
Access-Control-Allow-Origin ❌ Missing Scoped origin (no wildcard) Access-Control-Allow-Origin missing Medium Access-Control-Allow-Origin: https://app.example.com
Information Disclosure
Check name Status Actual Expected Detail Severity Recommendation
Server ❌ Missing istio-envoy Header removed or generic Sensitive header exposed High Remove Server header or set to a generic token
X-Powered-By ✅ Passed Header removed Header not exposed High Remove X-Powered-By header
X-AspNet-Version ✅ Passed Header removed Header not exposed Medium Remove framework version headers
Raw headers
HTTP/2 200 
content-security-policy: default-src 'self' https://*.queue-it.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscentre.ca/ https://*.costcobusinesscenter.ca/ https://*.costco-static.com/ https://display.ugc.bazaarvoice.com/ https://api.bazaarvoice.com/; script-src 'self' https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.cdn-path.com/ https://h.costco.com/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com https://*.costcobusinesscenter.ca/ https://cdn.intake-lr.com/ https://cdn.cookielaw.org/ https://*.criteo.com/ http://*.criteo.com/ https://assets.adobedtm.com/ https://s.go-mpulse.net/ https://transcend-cdn.com/ https://apps.bazaarvoice.com/ https://display.ugc.bazaarvoice.com/ https://mobilecontent.costco.com/ https://mobilecontent-qa.costco.com/ https://*.pxlecdn.com https://*.pixlee.com https://*.pixlee.co 'unsafe-inline' 'unsafe-eval'; style-src 'self' https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://cdn.fonts.net/ 'unsafe-inline' https://transcend-cdn.com/ https://consent.costco.com/ https://consent.costco.ca/ https://consent.costco.com https://display.ugc.bazaarvoice.com/; img-src 'self' https://*.costcobusinessdelivery.com https://*.tiles.virtualearth.net/ https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://*.costco.ca/ https://*.costco.com/ https://*.costcotravel.com/ https://*.costcotravel.ca/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://cdn.cookielaw.org/ https://cm.everesttech.net/ https://dpm.demdex.net/ https://display.ugc.bazaarvoice.com https://retailmedia-static.azureedge.net https://retailmedia-static.azureedge.net/ https://network-a.bazaarvoice.com https://network-stg-a.bazaarvoice.com https://retailmedia-static.criteo.com/ blob: data:; media-src 'self' https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://cdn.bfldr.com/ https://*.contentstack.com/ https://*.costco-static.com/ https://*.criteo.net/ https://retailmedia-static.criteo.com/ https://*.criteo.net; font-src 'self' https://cdn.bfldr.com/ https://*.costco-static.com/ https://fonts.gstatic.com data:; object-src 'none'; base-uri 'self' about:; form-action 'self' https://*.cardinalcommerce.com https://www.cdn-path.com/ https://*.costcobusinessdelivery.com https://*.costco.ca/ https://*.costco.com/ https://r.intake-lr.com/ https://*.akstat.io https://*.opinionlab.com; frame-src https://*.cardinalcommerce.com https://www.cdn-path.com/ https://h.costco.com/ https://h.online-metrix.net/ https://*.cybersource.com/ https://*.costcobusinessdelivery.com https://*.costcobusinesscentre.ca/ https://*.ct-costco.com https://costco.demdex.net/ https://costco.centah.com/ https://consent-sync.costco.com/ https://consent-sync.costco.ca/ https://*.criteo.com/ http://*.criteo.com https://*.pixlee.com https://*.pixlee.co https://*.costco.com/ https://*.costco.ca/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/; connect-src 'self' https://h.costco.com/ https://cdn.bfldr.com/ https://*.dynatrace.com https://www.google.com/recaptcha/ https://gdx-api.costco.com https://gdx-npd.np.api.cc-costco.com https://api-tst.np.gdx.cc-costco.com https://dev.virtualearth.net/ https://sdk.virtualearth.net/ https://spatial.virtualearth.net/ https://*.queue-it.net/ https://*.costcobusinessdelivery.com/ https://*.costcobusinesscenter.ca/ https://*.costcobusinesscentre.ca/ https://*.costco.ca/ https://*.costco.com/ https://*.costco-static.com/ https://*.ct-costco.com https://cdn.cookielaw.org/ https://geolocation.onetrust.com/ https://costco.demdex.net/ https://dpm.demdex.net/ https://costco.tt.omtrdc.net/ https://*.criteo.com/ http://*.criteo.com/ https://*.criteo.net/ https://cm.everesttech.net/ https://r.intake-lr.com/ https://*.contentstack.com/ https://assets.adobedtm.com/ https://dcs.adobedc.net/ https://*.akstat.io https://*.go-mpulse.net/ https://*.akamaihd.net https://adobedc.demdex.net/ https://sync-transcend-cdn.com https://transcend-cdn.com/ https://telemetry.transcend.io/ https://telemetry.us.transcend.io/ https://privacyportal.onetrust.com/ https://consent.us.transcend.io/ https://api.bazaarvoice.com/ https://stg.api.bazaarvoice.com/; child-src 'self' blob: data:; upgrade-insecure-requests;
x-build-reference: 1.22.3-22734697192
x-build-tag: prd-usbc-release-v1.22.3
x-next-i18n-router-locale: en-us
x-middleware-rewrite: /en-us
x-nextjs-cache: HIT
etag: "d1pz6eidr723spo"
content-type: text/html; charset=utf-8
x-envoy-upstream-service-time: 131
server: istio-envoy
x-costco-gdx-deployment: blue
x-costco-gdx-backend: external-web-backend
expires: Tue, 10 Mar 2026 20:10:30 GMT
cache-control: max-age=0, no-cache, no-store
pragma: no-cache
date: Tue, 10 Mar 2026 20:10:30 GMT
set-cookie: akavpau_zezxapz5yf=1773173730~id=a7ef94cd70880256732654e9e330ae45; Domain=www.costco.com; Path=/; Secure; SameSite=None
set-cookie: akaas_AS01=2147483647~rv=87~id=8d51425b09913196ebd01f5db5ffeb62; path=/; Secure; SameSite=None
strict-transport-security: max-age=31536000;includeSubDomains
set-cookie: _abck=F639C64530D4600E9D6DAB2335799CDA~-1~YAAQf1ATAnp8fNecAQAARFlf2Q/MZkLP17JBN/UE8rXmQl6Jobusi+S0M3ajzrhgG5Q1s7nJFrs70pcfXdV0+woRZQpEKUYPAEWH0GSpf/2d+RDof2aofJVf4Dd2VHRHXd6QOqG+UTyARbVnzSQpFr/hTsjuSk1Z+0G8xhgzSBk6WuMX7naaHT0epCAStVyP0wbqfqWPL1q5bVB3rOHb9Hz5BftUg0Mspoc0qoLra1v82FmL87o8x4GS6BA4ypjHMyGsmUJ1I3mQWZ3dcJF1CG/7gBB54F02LwYhLq/730cu0f8tpmB/9dxcTEyY3BOWG6xU4749BqHMhD/nnsTTfv5nKFmPEP+ufsoHm29j/VKrStFW+xsQ2GmDGnukthEh2OumuX7eT/tdiy726BnHANAGVWw5xAfgVo1K4GZxRACeB44CUfQyeRWLV8ErrHQvlNaBKD/aMQk=~-1~-1~-1~-1~-1; Domain=.costco.com; Path=/; Expires=Wed, 10 Mar 2027 20:10:30 GMT; Max-Age=31536000; Secure
set-cookie: bm_sz=009AECE71F1CD987390315E6BCF6925C~YAAQf1ATAnt8fNecAQAARFlf2R8pVYoBWNUE8nW4+iCicGeIsVnzbADtaVr1f/4XTUD+0QMXbwqbmW6Roz0Bq29CWe0ThELCkaJkZuutROAQEShmdS+KOrJN5CVB28RWu4u2mjd+sc7hpAnNGO/RxtiKLwPaLIz7OYFaOsmCgukVgwQ0gd0laPDcqT1zfswoD5vPcqEk4s8LBbstn1Xp3ra7Fnppe786VcN4acE/IvvACJlVq0pzDuVlvj3r/fda5bkrHqXpP6ZltGfIN2dNzw4NQafrkwg4lZ3aNTC5wHCgeoPZSrR9MeJWFUiH72F06KofwaTpRYNL+u1wyqPKu9QAdIk+v1nmWLFqnpJWpRHXsNpvoA==~3356216~3224641; Domain=.costco.com; Path=/; Expires=Wed, 11 Mar 2026 00:10:30 GMT; Max-Age=14400
server-timing: ak_p; desc="1773173430506_34820223_10955312_3413_23849_33_27_15";dur=1