Cookiesentry
Cookie checkerGDPR docsFeaturesPricingBlogContact

The Cookies Guide

A searchable directory of the cookies you'll actually find in the wild: 104 cookie entries from 30 providers, with purpose, expiry, source, and compliance context.

Look it up fast

Found a cookie like _fbp or _shopify_s? Search the table below to see what it does and who set it.

Know what needs consent

Analytics, advertising, and social cookies usually require prior consent. Functional cookies need a case-by-case necessity assessment.

Use it in audits

Use these entries to reconcile your CMP, privacy notice, and scan results before regulators, clients, or procurement teams ask questions.

Showing 104 of 104 cookies

CookiePurposeExpiryCopy
_ga
Google AnalyticsAnalytics

Google LLC

Distinguishes unique users by assigning a randomly generated client ID. Used by both Universal Analytics and GA4 properties.

2 years
_ga_<container-id>
Google AnalyticsAnalytics

Google LLC

GA4 session state cookie. Stores the current session ID and engagement state for the property; one is set per GA4 measurement ID.

2 years
_gid
Google AnalyticsAnalytics

Google LLC

Used by Universal Analytics to distinguish users over a 24-hour window. Largely deprecated since GA4 but still found on legacy sites.

24 hours
_gat
Google AnalyticsAnalytics

Google LLC

Throttles the request rate to Google Analytics on high-traffic sites. Often appears as _gat_gtag_<id>.

1 minute
_dc_gtm_<container-id>
Google AnalyticsAnalytics

Google LLC

Used by Google Tag Manager to throttle the request rate to Google Analytics. Set when GTM loads GA on the page.

1 minute
_gcl_au
Google AdsAdvertising

Google LLC

Google Ads conversion-linker cookie. Stores ad-click information so conversions can be attributed outside Google's domain.

3 months
_gcl_aw
Google AdsAdvertising

Google LLC

Google Ads click-through cookie set when a visitor lands on the site from a Google search ad. Used for attribution.

3 months
_gcl_dc
Google AdsAdvertising

Google LLC

Google Ads / DoubleClick click-through cookie set when a visitor arrives from a Display Network ad.

3 months
_gcl_gs
Google AdsAdvertising

Google LLC

Set by Google's Consent Mode v2 to store the timestamp of a Google Ads click when ad-storage consent has been granted. Used together with _gcl_gf to reconstruct attribution once the visitor consents.

90 days
_gcl_gf
Google AdsAdvertising

Google LLC

Google Consent Mode v2 cookie that captures the gclid (Google Click Identifier) at click time when ad-storage consent has been granted. Pairs with _gcl_gs for delayed attribution.

90 days
_gac_<property-id>
Google AdsAdvertising

Google LLC

Contains campaign-related information for the user. Linked to GA properties that have Google Ads auto-tagging enabled.

3 months
IDE
Google DoubleClickAdvertising

Google LLC

Used by Google DoubleClick to register and report on user actions after viewing or clicking an ad — for measuring effectiveness and serving targeted ads.

13 months
test_cookie
Google DoubleClickAdvertising

Google LLC

Set by doubleclick.net to determine if the user's browser supports cookies before serving ads.

15 minutes
DSID
Google DoubleClickAdvertising

Google LLC

Used by Google DoubleClick to identify a signed-in user across non-Google sites and remember whether they consented to ad personalisation.

2 weeks
NID
GoogleAdvertising

Google LLC

Contains a unique ID Google uses to remember preferences (preferred language, ad personalisation) and to show targeted ads on Google services and across the web.

6 months
CONSENT
GoogleFunctional

Google LLC

Records the visitor's consent decisions on Google properties. Set on google.com and propagated to embedded YouTube, reCAPTCHA, and Maps.

2 years
1P_JAR
GoogleAdvertising

Google LLC

Used by Google to gather website statistics and track conversion rates. Set when Google domains are embedded (YouTube, reCAPTCHA, Maps).

1 month
SOCS
GoogleFunctional

Google LLC

Stores the user's consent state for Google services (e.g. cookie-banner choices on YouTube, Search). Read by Google embeds on third-party sites.

13 months
SID
GoogleAdvertising

Google LLC

Google account session cookie. On third-party sites (via YouTube, Maps, or reCAPTCHA embeds) it enables Google to identify a signed-in visitor across the web — a tracking-capable identifier that requires consent in EU/UK contexts.

2 years
HSID
GoogleAdvertising

Google LLC

Companion to SID, signed to prevent forgery. On third-party sites surfaced through Google embeds, it contributes to cross-site visitor identification and ad personalisation.

2 years
__Secure-1PSID
GoogleAdvertising

Google LLC

Secure first-party variant of the Google account session cookie. When surfaced on a third-party site through a Google embed, it enables Google to identify the visitor across the web for ad and product personalisation.

2 years
__Secure-3PSID
GoogleAdvertising

Google LLC

Third-party variant of the Google account session cookie. Enables Google to deliver personalised ads across non-Google sites.

2 years
_fbp
MetaAdvertising

Meta Platforms Ireland Ltd.

Set by Meta Pixel (used by both Facebook and Instagram Ads) to identify browsers for ad delivery, conversion tracking, and remarketing.

3 months
_fbc
MetaAdvertising

Meta Platforms Ireland Ltd.

Stores the last-click ID (fbclid) from a Facebook or Instagram ad that brought the visitor to the site. Used for ad attribution and conversion tracking.

3 months
_fbq
MetaAdvertising

Meta Platforms Ireland Ltd.

Alternative cookie name occasionally written by older Meta Pixel deployments and tag-manager templates. Functionally interchangeable with _fbp — used to identify the browser for ad delivery and conversion tracking. If both _fbp and _fbq appear on the same site, the pixel implementation is duplicated and should be consolidated.

3 months
fr
MetaAdvertising

Meta Platforms Ireland Ltd.

Set by facebook.com when Meta widgets are embedded (Like button, comments, login). Used to deliver ads, measure ad performance, and personalise ad content across Facebook and Instagram.

3 months
datr
MetaSocial Media

Meta Platforms Ireland Ltd.

Browser identifier set by facebook.com. On third-party sites that embed Meta widgets (Like button, comments, Login) it enables Meta to recognise the browser across sessions — a cross-site tracking signal that requires consent.

2 years
sb
MetaSocial Media

Meta Platforms Ireland Ltd.

Browser identifier used by Meta for account-recovery flows and authentication security. Surfaced on third-party sites through Meta embeds, contributing to cross-site visitor identification.

2 years
c_user
MetaSocial Media

Meta Platforms Ireland Ltd.

Stores the Facebook / Instagram user ID of the signed-in visitor. When a third-party page loads a Meta embed, the cookie is sent to Meta — directly identifying the visitor across the web.

1 year
xs
MetaSocial Media

Meta Platforms Ireland Ltd.

Session token authenticating signed-in Facebook / Instagram users. Sent to Meta from any third-party page embedding a Meta widget while the visitor is logged in to Meta.

1 year
wd
MetaFunctional

Meta Platforms Ireland Ltd.

Stores the visitor's browser window dimensions so Meta can render embeds at the correct size. Set on facebook.com.

1 week
presence
MetaFunctional

Meta Platforms Ireland Ltd.

Stores the visitor's chat and presence state for Facebook Messenger / Instagram Direct. Session-only.

Session
locale
MetaFunctional

Meta Platforms Ireland Ltd.

Stores the user's language preference for Meta-rendered content (Like button, embeds, Messenger).

1 week
_ttp
TikTokAdvertising

TikTok Information Technologies UK Ltd.

TikTok Pixel cookie used to track conversions, optimise ad delivery, and build remarketing audiences.

13 months
ttwid
TikTokAdvertising

TikTok Information Technologies UK Ltd.

TikTok web identifier used for analytics and ad performance measurement across the TikTok ad network.

1 year
_tt_enable_cookie
TikTokAdvertising

TikTok Information Technologies UK Ltd.

Set by TikTok Pixel to confirm whether the visitor's browser will accept TikTok cookies before firing tracking events.

13 months
tt_csrf_token
TikTokSocial Media

TikTok Information Technologies UK Ltd.

CSRF protection token issued by TikTok. Although strictly necessary for TikTok-side interactions, on a third-party site it appears only when a TikTok video embed loads — making it part of the social-plugin tracking stack.

Session
tt_chain_token
TikTokSocial Media

TikTok Information Technologies UK Ltd.

Internal TikTok request-routing token used to chain related requests across a session. On third-party sites it surfaces through TikTok embeds and contributes to cross-site identification.

Session
tt_webid_v2
TikTokAdvertising

TikTok Information Technologies UK Ltd.

Persistent TikTok web visitor ID used for cross-session attribution and ad measurement.

1 year
li_sugr
LinkedInAdvertising

LinkedIn Ireland Unlimited Company

Used by LinkedIn Insight Tag to make a probabilistic match of a visitor's identity outside the designated countries.

3 months
bcookie
LinkedInAdvertising

LinkedIn Ireland Unlimited Company

LinkedIn browser ID cookie used to identify devices accessing LinkedIn for analytics, ad measurement, and personalisation.

1 year
bscookie
LinkedInAdvertising

LinkedIn Ireland Unlimited Company

Secure browser ID used for LinkedIn account security. On third-party sites it surfaces through LinkedIn embeds and forms part of LinkedIn's cross-site identity layer used for ad measurement and remarketing.

1 year
lidc
LinkedInFunctional

LinkedIn Ireland Unlimited Company

LinkedIn datacenter-routing cookie. Required for LinkedIn-rendered embeds to function correctly. Limited to load-balancing — case-by-case necessity assessment usually applies.

24 hours
UserMatchHistory
LinkedInAdvertising

LinkedIn Ireland Unlimited Company

Used by LinkedIn for ID-syncing of advertising campaigns across user devices.

1 month
AnalyticsSyncHistory
LinkedInAnalytics

LinkedIn Ireland Unlimited Company

Stores information about the time a visitor's identity was synchronised with the lms_analytics cookie for LinkedIn analytics.

1 month
li_gc
LinkedInFunctional

LinkedIn Ireland Unlimited Company

Stores the visitor's consent decisions for use of non-essential cookies on LinkedIn properties.

6 months
personalization_id
X (Twitter)Advertising

X Corp.

Used by X (formerly Twitter) to integrate and share features for social media and to personalise content and ads across the X ad network.

2 years
guest_id
X (Twitter)Advertising

X Corp.

Used by X to identify and track website visitors (including non-logged-in users) for embedded content, analytics, and ads.

2 years
muc_ads
X (Twitter)Advertising

X Corp.

Set by X to measure and improve the relevance of advertising shown on the X platform and via the X Audience Platform on third-party sites.

2 years
gt
X (Twitter)Functional

X Corp.

Guest token used by X to authorise non-logged-in visitors when loading embedded tweets and timelines. Required for the embed to render — case-by-case necessity assessment when the embed itself is optional.

Session
_pinterest_sess
PinterestAdvertising

Pinterest Europe Ltd.

Used by Pinterest for tracking purposes and to enable users to share content via the Pinterest social network.

1 year
_pin_unauth
PinterestAdvertising

Pinterest Europe Ltd.

Pinterest uses this cookie to group actions for users who cannot be identified by Pinterest (non-logged-in visitors).

1 year
_pinterest_ct_ua
PinterestAdvertising

Pinterest Europe Ltd.

Used by the Pinterest conversion tag to attribute on-site events to Pinterest ad campaigns.

1 year
_scid
SnapchatAdvertising

Snap Group Limited

Snapchat Pixel browser identifier used to track conversions and measure the effectiveness of Snapchat ads.

13 months
sc_at
SnapchatAdvertising

Snap Group Limited

Snapchat authentication / ad-attribution cookie used to associate visitors with Snapchat ad clicks.

1 year
_rdt_uuid
RedditAdvertising

Reddit, Inc.

Reddit Pixel visitor identifier. Used to measure conversions, build remarketing audiences, and attribute on-site events to Reddit ad clicks.

3 months
cto_bundle
CriteoAdvertising

Criteo SA

Criteo's primary retargeting cookie. Stores an encoded bundle that links the visitor to Criteo's ad-bidding profile for personalised display ads.

13 months
cto_tld_test
CriteoAdvertising

Criteo SA

Used by Criteo to determine the highest-level domain on which it can set cookies. Set briefly during the test, then expires.

Session
cto_idcpy
CriteoAdvertising

Criteo SA

Stores a Criteo identifier copied from a related domain to maintain retargeting state across multiple TLDs.

13 months
cto_sid
CriteoAdvertising

Criteo SA

Criteo session identifier used to deduplicate ad impressions and conversion events within a single browsing session.

Session
_uetsid
Microsoft AdvertisingAdvertising

Microsoft Corporation

Microsoft Bing Ads UET (Universal Event Tracking) session cookie. Used for conversion measurement and audience building for Bing/Microsoft Ads campaigns.

1 day
_uetvid
Microsoft AdvertisingAdvertising

Microsoft Corporation

Microsoft Bing Ads UET visitor cookie. Persistent ID used for cross-session attribution and remarketing for Microsoft Advertising.

13 months
MUID
Microsoft AdvertisingAdvertising

Microsoft Corporation

Microsoft user identifier set on bing.com and microsoft.com. Used for user identification, ad personalisation, and analytics across Microsoft properties — including Bing Ads on third-party sites.

13 months
SRM_B
Microsoft AdvertisingAdvertising

Microsoft Corporation

Set by bing.com to register a unique ID that identifies a returning user's device for Bing Ads remarketing.

13 months
ANONCHK
Microsoft AdvertisingAdvertising

Microsoft Corporation

Used by Microsoft Clarity / Bing to validate analytics data and prevent fraudulent UET event submissions.

10 minutes
MR
Microsoft AdvertisingAdvertising

Microsoft Corporation

Used by Microsoft to indicate whether to refresh the MUID cookie. Supports Bing Ads attribution and audience syncing.

1 week
_hjSessionUser_<id>
HotjarAnalytics

Hotjar Ltd.

Hotjar user ID cookie. Ensures data from subsequent visits to the same site is attributed to the same user.

1 year
_hjSession_<id>
HotjarAnalytics

Hotjar Ltd.

Hotjar session cookie. Holds current session data so subsequent requests in the session window are attributed correctly.

30 minutes
_hjFirstSeen
HotjarAnalytics

Hotjar Ltd.

Identifies a new user's first session and indicates whether or not Hotjar's seeing this user for the first time.

30 minutes
_hjIncludedInPageviewSample
HotjarAnalytics

Hotjar Ltd.

Set so Hotjar can determine whether the visitor is included in the data sampling defined by the site's pageview limit.

30 minutes
_hjAbsoluteSessionInProgress
HotjarAnalytics

Hotjar Ltd.

Used by Hotjar to detect a visitor's first pageview session and prevent it being counted multiple times.

30 minutes
_hjOptedOut
HotjarFunctional

Hotjar Ltd.

Records that the visitor has opted out of Hotjar tracking via the provider's universal opt-out endpoint. While set, Hotjar will not record new sessions, recordings, or surveys for the browser. Functional rather than analytics: it exists specifically to suppress tracking, not to enable it.

1 year
_clck
Microsoft ClarityAnalytics

Microsoft Corporation

Persists the Clarity user ID and preferences unique to the site, so visits to the same site are attributed to the same user.

1 year
_clsk
Microsoft ClarityAnalytics

Microsoft Corporation

Connects multiple Clarity page views by a user into a single session recording.

24 hours
ajs_anonymous_id
SegmentAnalytics

Twilio Inc. (Segment)

Segment-generated anonymous visitor identifier. Used to attribute events from non-logged-in users to a stable ID across sessions before they identify.

1 year
ajs_user_id
SegmentAnalytics

Twilio Inc. (Segment)

Segment user identifier set after a visitor calls analytics.identify(). Used to forward identified events to downstream tools (Mixpanel, Amplitude, etc.).

1 year
amplitude_id_<id>
AmplitudeAnalytics

Amplitude, Inc.

Stores the Amplitude device and user ID, plus session metadata, so behavioural events can be attributed to a stable user across visits.

10 years
optimizelyEndUserId
OptimizelyAnalytics

Optimizely, Inc.

Optimizely visitor identifier used to bucket users into A/B test variants and measure experiment exposure consistently across visits.

6 months
__hstc
HubSpotAnalytics

HubSpot, Inc.

HubSpot main analytics cookie tracking visitors. Contains domain, utk, initial timestamp, last timestamp, current timestamp, and session number.

6 months
hubspotutk
HubSpotAnalytics

HubSpot, Inc.

HubSpot user token. Identifies a unique visitor and is passed to HubSpot on form submission for contact deduplication.

6 months
__hssc
HubSpotAnalytics

HubSpot, Inc.

HubSpot session cookie. Tracks sessions: incremented on each new pageview within 30 minutes.

30 minutes
__hssrc
HubSpotAnalytics

HubSpot, Inc.

HubSpot session-restart flag. Set to 1 when HubSpot detects that the visitor has started a new browser session.

Session
messagesUtk
HubSpotFunctional

HubSpot, Inc.

HubSpot Messages identifier. Used by the HubSpot chat widget to recognise returning visitors and continue prior chat threads.

6 months
intercom-id-<app_id>
IntercomFunctional

Intercom R&D Unlimited Company

Anonymous Intercom visitor identifier used to maintain conversation history for non-logged-in users.

9 months
intercom-session-<app_id>
IntercomFunctional

Intercom R&D Unlimited Company

Identifies a logged-in Intercom user and grants access to Messenger and conversation history without re-authentication.

1 week
__cf_bm
CloudflareEssential

Cloudflare, Inc.

Cloudflare bot-management cookie. Distinguishes bots from human visitors and is necessary for site security and Bot Management.

30 minutes
__cfruid
CloudflareEssential

Cloudflare, Inc.

Cloudflare rate-limiting cookie. Used to identify trusted web traffic and protect origin servers from abuse.

Session
cf_clearance
CloudflareEssential

Cloudflare, Inc.

Set after a visitor passes a Cloudflare challenge (CAPTCHA, JavaScript challenge, Managed Challenge). Required for site access.

30 minutes to 1 year (configurable)
__stripe_mid
StripeEssential

Stripe Payments Europe Ltd.

Stripe machine-identifier cookie used for fraud prevention on payment forms.

1 year
__stripe_sid
StripeEssential

Stripe Payments Europe Ltd.

Stripe session-identifier cookie used for fraud prevention on payment forms.

30 minutes
ts_c
PayPalEssential

PayPal (Europe) S.à r.l. et Cie, S.C.A.

PayPal fraud-prevention and security cookie used during checkout.

3 years
_shopify_y
ShopifyAnalytics

Shopify International Ltd.

Shopify long-term visitor analytics cookie used for tracking returning customers and personalising recommendations.

1 year
_shopify_s
ShopifyAnalytics

Shopify International Ltd.

Shopify session analytics cookie used to track the current visit.

30 minutes
cart
ShopifyEssential

Shopify International Ltd.

Shopify shopping-cart identifier used to associate cart contents with the visitor's browser.

2 weeks
_secure_session_id
ShopifyEssential

Shopify International Ltd.

Shopify secure session cookie used for checkout and authenticated areas of the storefront.

24 hours
woocommerce_cart_hash
WooCommerceEssential

Automattic, Inc.

WooCommerce cart-hash cookie. Indicates when the cart contents change so the front-end can reload cart fragments.

Session
woocommerce_items_in_cart
WooCommerceEssential

Automattic, Inc.

WooCommerce cart-items counter. Tracks the number of items currently in the cart.

Session
wp_woocommerce_session_<hash>
WooCommerceEssential

Automattic, Inc.

WooCommerce session cookie. Holds a unique code for the customer so cart and order data can be retrieved from the database.

2 days
wordpress_logged_in_<hash>
WordPressEssential

WordPress Foundation

Set when a user logs in to WordPress. Used by the WordPress interface to keep the user signed in.

Session or 14 days (with Remember Me)
wp-settings-<user_id>
WordPressFunctional

WordPress Foundation

Persists logged-in WordPress users' admin interface preferences (e.g., dashboard layout).

1 year
PrestaShop-<hash>
PrestaShopEssential

PrestaShop SA

PrestaShop session cookie. Stores cart, user, and language state for the storefront.

20 days
PHPSESSID
PHP / Magento / DrupalEssential

Site operator

PHP session-identifier cookie. Used by PHP-based platforms (Magento, Drupal, custom apps) to maintain user session state.

Session
_mcid
MailchimpAdvertising

The Rocket Science Group LLC

Mailchimp marketing cookie used to identify the visitor and link form submissions to a Mailchimp audience.

1 year
__kla_id
KlaviyoAdvertising

Klaviyo, Inc.

Klaviyo identifier cookie. Tracks the visitor across sessions for email campaign attribution and audience syncing.

2 years

How cookies are categorised

Essential

Strictly necessary for the site to function, such as login sessions, carts, security challenges, or payment continuity. These can be exempt from consent if the necessity test is genuinely met.

Functional

Preference, support, or convenience features. These are not automatically exempt and often need a case-by-case review with legal or DPO input.

Analytics

Traffic and behavior measurement cookies such as Google Analytics, Hotjar, and Clarity. In the EU these generally require prior consent.

Advertising

Retargeting, attribution, and audience building cookies such as Meta Pixel or Google Ads. These should not load before explicit opt-in.

Social media

Set by embeds, social login, and platform widgets. These are usually third-party tracking technologies and should be blocked until consent or explicit interaction.

Explore by compliance intent

These hub pages target the questions privacy teams, marketers, and site owners actually search for.

Cookies that require consent

77 cookies

Reference page for cookies that require prior consent under GDPR and ePrivacy, including analytics, advertising, and social media technologies.

Cookies that do not require consent

14 cookies

Guide to cookies that may fall under the strict necessity exemption, plus the documentation and audit controls still required under GDPR and ePrivacy.

Shopify

4 cookies

Detailed reference for Shopify cookies, including storefront, session, analytics, and checkout-related cookies, plus GDPR audit guidance for merchants and agencies.

WordPress

2 cookies

Guide to WordPress cookies, including core login and preference cookies, plus GDPR advice for plugin-heavy WordPress websites.

WooCommerce

5 cookies

Reference guide for WooCommerce cookies covering cart, checkout, session, and store functionality, plus GDPR controls for ecommerce stores.

PrestaShop

1 cookies

Guide to PrestaShop cookies, GDPR obligations, and audit checks for merchants using modules, embedded services, and ecommerce tracking.

Essential

14 cookies

Reference guide to essential cookies: what counts as strictly necessary, when consent is not required, and which implementation mistakes still create GDPR risk.

Functional

13 cookies

Detailed guide to functional cookies, including when they may need consent, how regulators view preference and support widgets, and what to document in your banner and policy.

Analytics

23 cookies

Guide to analytics cookies such as Google Analytics, Hotjar, and Microsoft Clarity, with GDPR consent rules, audit checks, and implementation pitfalls.

Advertising

48 cookies

Reference guide to advertising cookies like Meta Pixel, Google Ads, TikTok, and LinkedIn, with clear GDPR consent requirements and remediation advice.

Social Media

6 cookies

Guide to social media cookies set by embedded content, social login, and sharing tools, including why they usually require consent in the EU.

Want to know which of these are on your site?

CookieSentry scans your website, identifies every cookie set before consent, and shows which ones create GDPR and ePrivacy exposure. Free scan, no signup needed.

Run a free scan →

Cookie names, expiry windows, and descriptions are based on public vendor documentation and observed behavior as of 2026. Providers can change this without notice. This guide is a practical reference, not legal advice.

Cookiesentry
About usFAQContactBlogCookies GuideAlternativesFree toolsGDPR GuidesPrivacyTermsEU Hosting

No cookies. No tracking. Analytics by EU-hosted Umami.

© 2025 CookieSentry. All rights reserved. Made with care for your privacy.