Skip to content

Reference

Cookie encyclopedia

What a cookie is for, who set it, and whether it is necessary. Every entry cites a source and carries a review date.

NameProviderPurposeNecessaryConfidence
_gaGoogleDistinguishes browsers for analytics; persists for around two yearsNoVerified
_gidGoogleDistinguishes browsers; roughly 24 hoursNoVerified
_fbpMetaAdvertising attribution across sitesNoVerified
_gcl_auGoogleConversion attribution for AdsNoVerified
IDEGoogle (DoubleClick)Ad targeting and measurementNoVerified
MUIDMicrosoftIdentifies a browser across Microsoft propertiesNoVerified
_clck / _clskMicrosoft ClaritySession analytics and replay associationNoVerified
__cf_bmCloudflareBot management; short livedYesVerified
__Host-next-auth.csrf-tokenSite itselfCross-site request forgery protectionYesVerified
__stripe_midStripeFraud prevention during paymentYesVerified
PHPSESSIDSite itselfServer-side session identifierYesVerified
li_sugrLinkedInProbabilistic browser identification for adsNoHigh

Notice how many of the necessary ones are security features. "Reject all cookies" would break payment fraud checks and CSRF protection — a genuinely worse outcome than the advertising cookie you were trying to avoid.

Spotted an error? Corrections are welcome at info@sessyn.com and we publish what we change.

Last reviewed: 2026-09-12