If you are using the https then parse the client.cookieJar=null; or cookie=' '; in the headers of http call then it will not accept the cookies and invalid characters from it
And you can use Dio interceptor instead of the http to make API calls it defaults not accept the cookies in API call