That sounds like a great way to do it.
But I would just use CFCOOKIE to set the cookie of your own project.
The two servers will need to share the domain name, of course, in order to be able to read the same cookie. You also need to set a cookie as a domain cookie.
One clean way to create this archive would be to create an entire CFC dedicated to security.
He would have methods for generating and checking input tokens.
CF , node.js -
http:
, , , / ( ) , node.js .
, mongodb (CF, Java Rails). CF . , , //etc, .