The cookie will probably not be updated because it's on a different domain.
Contacts and authentication are different things, a contact can be connected to a user. But doesn't need to be the other way around.
How did you configure the "Authorisation: WWW only, shared for * subdomain"