Anonymous browser token
A random token is created in the participant’s browser. It is kept in browser storage when available and in a necessary first-party, HttpOnly cookie so restricted in-app browsers can keep the same voting identity. The server hashes the token before storage and rejects another ballot using the same token.