Cloudflare sets 3 cookies on websites that load its scripts. Below is the full list with purpose, expiry, and whether each one needs GDPR / ePrivacy consent.
__cf_bmEssentialExpires: 30 minutesCloudflare bot-management cookie. Distinguishes bots from human visitors and is necessary for site security and Bot Management.
__cfruidEssentialExpires: SessionCloudflare rate-limiting cookie. Used to identify trusted web traffic and protect origin servers from abuse.
cf_clearanceEssentialExpires: 30 minutes to 1 year (configurable)Set after a visitor passes a Cloudflare challenge (CAPTCHA, JavaScript challenge, Managed Challenge). Required for site access.
CookieSentry scans your site, identifies every Cloudflare cookie set before consent, and gives you an evidence-grade PDF for your DPO.
Run a free scan →