Reference
Cookie encyclopedia
What a cookie is for, who set it, and whether it is necessary. Every entry cites a source and carries a review date.
| Name | Provider | Purpose | Necessary | Confidence |
|---|---|---|---|---|
| _ga | Distinguishes browsers for analytics; persists for around two years | No | Verified | |
| _gid | Distinguishes browsers; roughly 24 hours | No | Verified | |
| _fbp | Meta | Advertising attribution across sites | No | Verified |
| _gcl_au | Conversion attribution for Ads | No | Verified | |
| IDE | Google (DoubleClick) | Ad targeting and measurement | No | Verified |
| MUID | Microsoft | Identifies a browser across Microsoft properties | No | Verified |
| _clck / _clsk | Microsoft Clarity | Session analytics and replay association | No | Verified |
| __cf_bm | Cloudflare | Bot management; short lived | Yes | Verified |
| __Host-next-auth.csrf-token | Site itself | Cross-site request forgery protection | Yes | Verified |
| __stripe_mid | Stripe | Fraud prevention during payment | Yes | Verified |
| PHPSESSID | Site itself | Server-side session identifier | Yes | Verified |
| li_sugr | Probabilistic browser identification for ads | No | High |
Notice how many of the necessary ones are security features. "Reject all cookies" would break payment fraud checks and CSRF protection — a genuinely worse outcome than the advertising cookie you were trying to avoid.
Spotted an error? Corrections are welcome at info@sessyn.com and we publish what we change.
Last reviewed: 2026-09-12