Our Supported Integrations
Consentify seamlessly integrates with popular analytics and marketing tools. Manage consent for each service and stay compliant with GDPR, CCPA and ePrivacy.
How Integrations Work
Our system ensures that these scripts are only loaded after a user provides their explicit consent, helping you maintain compliance with GDPR, CCPA and ePrivacy.
Analytics Integrations
Google Analytics
Google Analytics helps you understand how visitors engage with your website, providing data on traffic, user behavior, and conversions.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _ga, _ga_* | customer_domain | Used to distinguish users and has a default expiration of 2 years. | 2 years |
| _gid | customer_domain | Used to distinguish users and has a 24-hour expiration. | 24 hours |
| _gat_* | customer_domain | Used to throttle request rate. | 1 minute |
Microsoft Clarity
Microsoft Clarity records sessions and builds heatmaps so you can see how visitors actually move through your pages. It is free to use and very widely installed.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _clck | customer_domain | Stores a Clarity user ID and a cookie preference flag so sessions from the same visitor are grouped together. | 1 year |
| _clsk | customer_domain | Links multiple page views from one visitor into a single session recording. | 1 day |
| CLID | clarity.ms | Identifies the first time Clarity saw this visitor on any site using Clarity. | 1 year |
Hotjar
Hotjar combines heatmaps, session recordings and on-site surveys to show where visitors click, scroll and drop off.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _hjSessionUser_* | customer_domain | Stores a Hotjar user ID so the same visitor is recognised on later visits. | 1 year |
| _hjSession_* | customer_domain | Holds the current session data for the recording. | 30 minutes |
| _hjIncludedInSessionSample_* | customer_domain | Marks whether this visitor was picked for the site's recording quota. | 2 minutes |
Matomo
Matomo is a self-hosted or EU-hosted analytics platform, often chosen when data has to stay in Europe. Enter your Matomo URL and site ID separated by a comma, for example https://ditt-navn.matomo.cloud/,1
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _pk_id.* | customer_domain | Stores a visitor ID and the timestamps used to recognise returning visitors. | 13 months |
| _pk_ses.* | customer_domain | Short-lived cookie that groups page views into one visit. | 30 minutes |
Plausible Analytics
Plausible is a lightweight analytics tool from the EU that counts visits without cookies and without collecting personal data. Paste the script ID from Site installation, or your own domain if you are still on the older snippet.
No specific cookies declared for this integration.
Fathom Analytics
Fathom is a paid, privacy-first analytics service. The site ID is in Settings, in the Site ID column next to your site.
No specific cookies declared for this integration.
Simple Analytics
Simple Analytics recognises your site from the hostname the script runs on, so there is nothing to configure. Switch it on and add the site in your Simple Analytics account.
No specific cookies declared for this integration.
Umami
Umami is open source and often self-hosted. Paste the website ID from the tracking code. If you run your own Umami, add the URL after a comma.
No specific cookies declared for this integration.
GoatCounter
GoatCounter is open source and free for personal use. The code is the subdomain of your GoatCounter site, so mycode.goatcounter.com is just mycode.
No specific cookies declared for this integration.
Pirsch Analytics
Pirsch is a German, cookieless analytics service. The identification code is under Settings, Developer, in your Pirsch dashboard.
No specific cookies declared for this integration.
Cloudflare Web Analytics
Cloudflare Web Analytics is free and works without cookies. The token is in the beacon snippet Cloudflare gives you under Web Analytics.
No specific cookies declared for this integration.
Mixpanel
Mixpanel is a product analytics tool for tracking events, funnels and retention. Consentify loads it against the EU endpoint.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| mp_*_mixpanel | customer_domain | Stores the distinct ID, the current session and the properties Mixpanel attaches to events. | 1 year |
Amplitude
Amplitude is a product analytics platform for event tracking, funnels and cohort analysis. Loaded against the EU data region.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| AMP_* | customer_domain | Stores the Amplitude device ID, user ID and session ID used to stitch events together. | 1 year |
Segment
Segment collects events once and forwards them to your other tools. Gating it here means every downstream destination waits for consent too.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| ajs_anonymous_id | customer_domain | Anonymous visitor ID used to tie events together before the visitor is identified. | 1 year |
| ajs_user_id | customer_domain | Stores the identified user ID after a call to identify(). | 1 year |
FullStory
FullStory records full sessions and reconstructs what the visitor saw and clicked. It captures a lot, so consent matters.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| fs_uid | customer_domain | Stores the FullStory user and session ID so a recording can be tied to a returning visitor. | 1 year |
| fs_lua | customer_domain | Records the timestamp of the last user activity. | 30 minutes |
Smartlook
Smartlook records sessions and builds funnels, with an EU hosting region. Popular with e-commerce teams.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| SL_C_*_VID | customer_domain | Visitor ID used to recognise the same person across visits. | 1 year |
| SL_C_*_SID | customer_domain | Session ID for the current recording. | Session |
LogRocket
LogRocket replays sessions alongside console logs and network requests. Mostly used for debugging, but it still records the visitor.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _lr_* | customer_domain | Stores the LogRocket session and user ID used to link a recording to a visitor. | 1 year |
Heap
Heap captures every click and page view automatically, so you can define events after the fact instead of instrumenting up front.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _hp2_id.* | customer_domain | Stores the Heap user ID, session ID and page view ID for the visitor. | 13 months |
| _hp2_ses_props.* | customer_domain | Holds session properties such as the entry page. | 30 minutes |
Mouseflow
Mouseflow records sessions, heatmaps and form analytics. A Danish company, so data stays in the EU.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| mf_* | customer_domain | Identifies the recording session for the current visit. | Session |
Lucky Orange
Lucky Orange offers heatmaps, recordings and live chat in one script. Common on smaller e-commerce sites.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _lo_uid | customer_domain | Visitor ID used to recognise returning visitors. | 1 year |
| _lo_v | customer_domain | Counts the number of visits from this browser. | 1 year |
Crazy Egg
Crazy Egg produces click maps, scroll maps and confetti reports showing where visitors interact with a page.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _ceg.s | customer_domain | Tracks the current visit for heatmap sampling. | 3 months |
| _ceg.u | customer_domain | Stores a visitor ID used across sessions. | 3 months |
Siteimprove Analytics
Siteimprove Analytics is widely used across Nordic public sector sites, usually alongside their accessibility and quality assurance tooling.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| nmstat | customer_domain | Records which pages the visitor has viewed so Siteimprove can report on site usage. | 1000 days |
Contentsquare
Contentsquare provides AI-powered insights into customer behavior, helping businesses understand user journeys and optimize their digital experiences.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _cs_id | customer_domain | Stores technical user data including user ID, timestamps, session count, and device information. | 13 months |
| _cs_s | customer_domain | Stores session data including page views and session timing information. | Session duration |
| _cs_c | customer_domain | Stores user consent for data collection and use within session replays. | 13 months |
PostHog
PostHog is an open-source product analytics suite that includes analytics, session recording, feature flags, and A/B testing.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| ph_*_posthog | customer_domain | Stores user identification data including distinct ID, session ID, and other tracking information for analytics. | 1 year |
Shopify Analytics
Shopify's own storefront analytics. These are set by Shopify's servers, so they cannot be held back from here — turn them off in the store's customer privacy settings instead.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _shopify_y | Shopify | Identifies the visitor for storefront analytics. | 1 year |
| _shopify_s | Shopify | Identifies the visitor's session for storefront analytics. | 30 minutes |
| _shopify_sa_t | Shopify | Records the time of a visit for marketing attribution. | 30 minutes |
| _shopify_sa_p | Shopify | Records the source of a visit for marketing attribution. | 30 minutes |
Marketing & Ads Integrations
Google Ads
Google Ads conversion tracking measures actions people take after clicking your ads, helping you understand which campaigns drive the most valuable customer activity.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _gcl_aw | customer_domain | Stores Google Click ID (gclid) when a user arrives from a Google Ad. Used for conversion tracking and attribution. | 90 days |
| _gcl_dc | customer_domain | Stores DoubleClick click ID for cross-network conversion attribution. | 90 days |
| _gcl_gb | customer_domain | Stores Google Ads click ID for Enhanced Conversions, linking on-site actions to ad clicks. | 90 days |
Facebook Pixel
Facebook Pixel is an analytics tool that helps measure the effectiveness of advertising by understanding the actions people take on your website.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _fbp | customer_domain | First-party cookie used to store and track visits across websites for advertising, analytics, and measuring ad campaign effectiveness. | 90 days |
| _fbc | customer_domain | Stores Facebook click ID (fbclid) when a user arrives from a Facebook ad. Used for conversion tracking and attribution. | 90 days |
Google Tag Manager
Google Tag Manager is a tag management system that allows you to quickly and easily update measurement codes and related code fragments (tags) on your website or mobile app.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| N/A | customer_domain | Google Tag Manager does not set cookies by default. It manages tags from other services that may set their own cookies. Preview mode sets temporary first-party cookies for debugging. | N/A |
TikTok Pixel
TikTok Pixel helps you track website events, measure ad performance, and optimize your TikTok advertising campaigns.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _ttp | customer_domain | First-party cookie used to measure and improve advertising campaign performance and personalize the user experience on TikTok. | 13 months |
| _ttclid | customer_domain | Stores the TikTok Click ID when a user arrives from a TikTok ad. Used for conversion tracking and attribution. | Session |
LinkedIn Insight Tag
The LinkedIn Insight Tag enables website conversion tracking, website visitor retargeting, and unlocks additional insights about members interacting with your ads.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| li_fat_id | customer_domain | First-party cookie storing LinkedIn click ID for enhanced conversion tracking and attribution. Only set when Enhanced Conversion Tracking is enabled. | 30 days |
| lidc | linkedin.com | Used to facilitate data center selection and route user activity data to the appropriate LinkedIn data center. | 24 hours |
| bcookie | linkedin.com | Used for tracking the use of embedded services like share buttons and for browser identification. | 2 years |
Microsoft Advertising (UET)
The Microsoft Advertising UET tag measures conversions and builds remarketing audiences for Bing search ads. Common in B2B, where Bing traffic still converts well.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _uetsid | customer_domain | Identifies the current browsing session so conversions can be attributed to it. | 1 day |
| _uetvid | customer_domain | Identifies the visitor across sessions for remarketing and cross-device tracking. | 13 months |
| MUID | bing.com | Microsoft's cross-site identifier, used to recognise the browser across Microsoft properties. | 13 months |
Pinterest Tag
The Pinterest Tag measures conversions from Pinterest ads and builds audiences from site visitors. Strong on interior, fashion and food sites.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _pinterest_ct_ua | customer_domain | Stores a browser identifier used to attribute conversions to Pinterest ads. | 1 year |
| _epik | customer_domain | Stores the Pinterest click ID so a later conversion can be matched to the ad click. | 1 year |
X (Twitter) Pixel
The X (Twitter) conversion tag measures what visitors do after clicking an ad on X, and builds retargeting audiences.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| personalization_id | twitter.com | Identifies the browser across sites for ad personalisation and measurement. | 13 months |
| muc_ads | t.co | Used for ad measurement and conversion attribution. | 13 months |
Reddit Pixel
The Reddit Pixel tracks conversions from Reddit ads and builds retargeting audiences from site visitors.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _rdt_uuid | customer_domain | Stores a visitor ID used to attribute conversions to Reddit ad clicks. | 90 days |
Criteo
Criteo runs retargeting ads across publisher networks based on which products a visitor looked at. Heavily used in retail.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| cto_bundle | customer_domain | Stores a Criteo user identifier used to serve personalised retargeting ads. | 13 months |
| uid | criteo.com | Cross-site advertising identifier used to match the visitor across the Criteo network. | 13 months |
Taboola
Taboola runs native content recommendation ads and measures conversions from them. Mostly used by publishers and content marketers.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| t_gid | taboola.com | Cross-site identifier used to personalise recommended content and ads. | 1 year |
| taboola_session_id | customer_domain | Identifies the current session for conversion attribution. | Session |
Snapchat Pixel
Snapchat Pixel helps measure the impact of your Snapchat campaigns, optimize your ads, and build more effective audience segments.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _scid | customer_domain | First-party cookie storing a unique identifier for the user to track conversions and website activity across visits. | 13 months |
| _schn | customer_domain | Session cookie from Snapchat retargeting pixel used to track user interactions within a single session. | 1 day |
HubSpot
HubSpot tracking code identifies visitors and tracks their behavior across your site, feeding data into HubSpot CRM, forms, and marketing automation.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| __hstc | hubspot.com | Main cookie for tracking visitors. Contains domain, initial timestamp, last timestamp, current session start, and session number. | 13 months |
| hubspotutk | hubspot.com | Stores a unique token for the visitor, used for deduplication in HubSpot form submissions. | 13 months |
| __hssc | hubspot.com | Keeps track of sessions for analytics purposes. Contains domain, viewCount, and session start. | 30 minutes |
| __hssrc | hubspot.com | Set whenever HubSpot changes the session cookie. Used to determine whether the visitor has restarted their browser. | Session |
Klaviyo
Klaviyo powers email and SMS flows for e-commerce, and tracks on-site browsing so it can trigger abandoned cart and browse abandonment messages.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| __kla_id | customer_domain | Stores the visitor's Klaviyo profile ID and browsing activity used to trigger automated emails. | 2 years |
Mailchimp
Mailchimp's connected site script links website visits to email subscribers, enabling pop-up forms and abandoned cart automations. Paste the user ID and hash from the snippet, separated by a slash.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _mcid | customer_domain | Identifies the visitor so on-site activity can be linked to their Mailchimp contact. | 1 year |
| _mcida | customer_domain | Records the current session for the connected site script. | Session |
Brevo (Sendinblue)
Brevo handles email, SMS and marketing automation. The tracking script links page visits to contacts so automations can react to on-site behaviour.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| sib_cuid | customer_domain | Stores a visitor ID so browsing activity can be matched to a Brevo contact. | 13 months |
ActiveCampaign
ActiveCampaign site tracking records which pages a known contact visits, so automations can be triggered on browsing behaviour.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| prospectId | customer_domain | Identifies the visitor so page views can be attached to their ActiveCampaign contact record. | 1 year |
Omnisend
Omnisend runs email and SMS automation for e-commerce, tracking browsing and cart activity to trigger recovery flows.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| omnisendAnonymousID | customer_domain | Anonymous visitor ID used to link browsing activity to an Omnisend contact. | 1 year |
| omnisendSessionID | customer_domain | Identifies the current session for on-site tracking. | 30 minutes |
Necessary Integrations
Consentify
Consentify stores the visitor's own cookie choices so the banner is not shown again on every page. Exempt from consent — it is the record of consent itself.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| csfy_consent | customer_domain | Stores which cookie categories the visitor accepted or refused, so the choice survives across pages and visits. | 1 year |
| csfy_consent (local storage) | customer_domain | The same choice kept in the browser's local storage, so it is still available when the banner starts before the cookie is read. | Until deleted |
| csfy_reported_routes (local storage) | customer_domain | Remembers which pages have already been checked for embedded content, so the same page is not reported twice. | Until deleted |
Stripe
Stripe is a payment processing platform. It sets cookies for fraud detection and secure payment sessions. No consent required under GDPR.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| __stripe_mid | Stripe | Fraud prevention — identifies the device across payment sessions. | 1 year |
| __stripe_sid | Stripe | Fraud prevention — identifies the browser session during checkout. | 30 minutes |
PayPal
PayPal is a global payment platform. Its cookies are strictly necessary for fraud detection and checkout session management.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| ts | PayPal | Fraud detection and risk assessment during checkout. | 3 years |
| JSESSIONID | PayPal | Session management required for the payment flow. | Session |
Klarna
Klarna is a buy-now-pay-later payment platform. Its cookies are strictly necessary for the checkout session.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| klarna-checkout-* | Klarna | Maintains the checkout session and selected payment method. | Session |
Google reCAPTCHA
Google reCAPTCHA protects forms from spam and abuse. It is strictly necessary for secure form submissions.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _GRECAPTCHA | Risk analysis for spam and bot detection. | 6 months |
Vipps MobilePay
Vipps MobilePay handles payment and login in the Nordics. Its cookies are needed to complete a payment and to protect against fraud, so no consent is required.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| vipps-* | Vipps MobilePay | Keeps the payment or login session alive while the visitor completes the flow. | Session |
| __Host-vipps-session | Vipps MobilePay | Secure session cookie used during checkout and Vipps login. | Session |
Cloudflare
Cloudflare sits in front of many sites as a CDN and bot filter. The cookies it sets are needed to tell real visitors from bots, and are exempt from consent.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| __cf_bm | Cloudflare | Bot management. Distinguishes human visitors from automated traffic. | 30 minutes |
| cf_clearance | Cloudflare | Stores the result of a passed challenge so the visitor is not challenged again. | 1 year |
| _cfuvid | Cloudflare | Separates individual visitors sharing an IP address so rate limits apply per visitor. | Session |
| __cflb | Cloudflare | Load balancing. Keeps the visitor on the same origin server for the duration of a session. | 24 hours |
| __cfruid | Cloudflare | Rate limiting. Identifies the request stream behind a shared IP address. | Session |
| __cfwaitingroom | Cloudflare | Holds the visitor's place in the queue when a waiting room is active. | Session |
Cloudflare Turnstile
Turnstile is a privacy-friendly alternative to CAPTCHA. It protects forms from abuse and is strictly necessary for secure submissions.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| cf_chl_* | Cloudflare | Temporary challenge state while the visitor is verified. | Session |
hCaptcha
hCaptcha protects forms from spam and automated abuse. Required for secure form submissions, so no consent is needed.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| hc_accessibility | hCaptcha | Remembers an accessibility cookie so the visitor can skip repeated challenges. | 30 days |
Shopify
Shopify stores cookies for the cart, checkout and store session. These are required for the shop to work and are exempt from consent. Shopify's analytics and marketing cookies are separate and still need consent.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| cart | customer_domain | Stores the contents of the visitor's shopping cart. | 2 weeks |
| _secure_session_id | customer_domain | Keeps the checkout session secure. | 24 hours |
| _shopify_m | customer_domain | Stores the visitor's own cookie and privacy preferences. | 1 year |
| _tracking_consent | customer_domain | Stores the visitor's tracking preferences as recorded by Shopify's own consent layer. | 1 year |
| secure_customer_sig | customer_domain | Keeps a logged-in customer signed in to their account. | 1 year |
| cart_currency | customer_domain | Remembers the currency the cart is priced in. | 2 weeks |
| cart_sig | customer_domain | Verifies that the cart has not been tampered with. | 2 weeks |
| localization | customer_domain | Remembers the country and language the visitor is shopping in. | 2 weeks |
| keep_alive | customer_domain | Preserves the visitor's session across regions during checkout. | 30 minutes |
WooCommerce
WooCommerce sets cart and session cookies on WordPress shops. They are required for the cart and checkout to function.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| woocommerce_cart_hash | customer_domain | Tells WooCommerce when the cart contents have changed. | Session |
| woocommerce_items_in_cart | customer_domain | Tracks whether the cart currently holds any items. | Session |
| wp_woocommerce_session_* | customer_domain | Holds a unique code for each customer so their cart data can be found in the database. | 2 days |
WordPress
WordPress sets cookies for login sessions, admin preferences and comment forms. They are set by the site itself and are required for it to work.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| wordpress_logged_in_* | customer_domain | Keeps a logged-in user signed in and identifies them to the site. | Session |
| wordpress_sec_* | customer_domain | Authenticates a logged-in user on secure areas of the site. | Session |
| wordpress_test_cookie | customer_domain | Checks whether the browser accepts cookies at all. | Session |
| wp-settings-* | customer_domain | Stores an editor's own interface preferences. | 1 year |
| wp-settings-time-* | customer_domain | Records when the interface preferences were last changed. | 1 year |
| wp_lang | customer_domain | Remembers the language chosen for the admin interface. | Session |
| wp-postpass_* | customer_domain | Remembers that the visitor entered the password for a protected post. | 10 days |
| comment_author_* | customer_domain | Pre-fills the name, e-mail and website fields the next time the visitor comments. | 1 year |
| wpEmojiSettingsSupports (session storage) | customer_domain | Records whether the browser can display emoji, so WordPress can skip loading a fallback. | Session |
Server session
The session and anti-forgery cookies a web framework sets to keep a visitor logged in and to protect forms against cross-site request forgery. Strictly necessary, and set by the site's own server.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| PHPSESSID | customer_domain | Identifies the visitor's session so the server can keep state between page loads. | Session |
| laravel_session | customer_domain | Identifies the visitor's session in a Laravel application. | 2 hours |
| XSRF-TOKEN | customer_domain | Protects forms against cross-site request forgery by tying a submission to the visitor's session. | Session |
| JSESSIONID | customer_domain | Identifies the visitor's session in a Java application. | Session |
| ASP.NET_SessionId | customer_domain | Identifies the visitor's session in an ASP.NET application. | Session |
| connect.sid | customer_domain | Identifies the visitor's session in a Node/Express application. | Session |
| sessionid | customer_domain | Identifies the visitor's session in a Django application. | 2 weeks |
| csrftoken | customer_domain | Protects forms against cross-site request forgery in a Django application. | 1 year |
Next.js
Next.js sets cookies for language routing and for previewing unpublished content. They are set by the site itself and carry no tracking.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| NEXT_LOCALE | customer_domain | Remembers the language version the visitor is reading. | 1 year |
| __prerender_bypass | customer_domain | Lets an editor see draft content instead of the published page. | Session |
| __next_preview_data | customer_domain | Holds the signed preview session for draft content. | Session |
Vercel
Vercel hosts the site. Its cookies handle deployment protection, preview access and keeping a visitor on one deployment while a release rolls out.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _vercel_jwt | Vercel | Grants access to a protected deployment after the visitor has authenticated. | Session |
| __vdpl | Vercel | Keeps the visitor on a single deployment during a release, so a page and its assets always match. | Session |
| __vercel_live_token | Vercel | Authenticates a visitor viewing a preview deployment. | Session |
| __vercel_toolbar | Vercel | Stores the state of the preview toolbar for the site's own team. | 1 year |
AWS Load Balancer
An Amazon load balancer sits in front of the site and keeps each visitor on the same server for the duration of a session. Required for the site to respond consistently.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| AWSALB | Amazon Web Services | Keeps the visitor on the same server behind the load balancer. | 7 days |
| AWSALBCORS | Amazon Web Services | The same routing information, for requests made across origins. | 7 days |
| AWSALBTG | Amazon Web Services | Routes the visitor to the same target group. | 7 days |
| AWSELB | Amazon Web Services | Keeps the visitor on the same server behind a classic load balancer. | Session |
Microsoft Azure
Azure routes the visitor to the same instance of the site for the duration of a session. Required for the site to respond consistently.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| ARRAffinity | Microsoft | Keeps the visitor on the same server instance. | Session |
| ARRAffinitySameSite | Microsoft | The same routing information, restricted to same-site requests. | Session |
| ApplicationGatewayAffinity | Microsoft | Keeps the visitor on the same server behind an application gateway. | Session |
Akamai
Akamai delivers the site and filters automated traffic. Its cookies are used to tell real visitors from bots and are exempt from consent.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| _abck | Akamai | Bot detection. Stores the result of the security assessment. | 1 year |
| ak_bmsc | Akamai | Bot detection. Distinguishes humans from automated traffic. | 2 hours |
| bm_sv | Akamai | Bot detection for the visitor's current session. | 2 hours |
| bm_sz | Akamai | Bot detection. Holds session data for the security check. | 4 hours |
Imperva (Incapsula)
Imperva is a web application firewall in front of the site. Its cookies are needed to keep a security session and to block attacks.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| incap_ses_* | Imperva | Identifies the visitor's session to the firewall. | Session |
| visid_incap_* | Imperva | Identifies the visitor across sessions so security decisions stay consistent. | 1 year |
| nlbi_* | Imperva | Load balancing between the servers behind the firewall. | Session |
Sucuri
Sucuri is a firewall and CDN in front of the site. Its cookie identifies a visitor that has passed the security check.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| sucuri_cloudproxy_uuid_* | Sucuri | Identifies a visitor that has already been cleared by the firewall. | Session |
WP Engine
WP Engine hosts the WordPress site. Its cookies handle caching and keeping an administrator signed in.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| wpe-auth | WP Engine | Keeps an administrator signed in to the hosting environment. | Session |
| wordpress_wpe_no_cache | customer_domain | Tells the cache to serve this visitor an uncached page, for example while logged in. | Session |
Functional Integrations
Intercom
Intercom is a customer messaging platform for live chat, support, and onboarding. It identifies and tracks logged-in users and visitors.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| intercom-id-* | Intercom | Anonymous visitor identifier used to recognize returning users across sessions. | 9 months |
| intercom-session-* | Intercom | Session identifier that keeps the chat window state between page loads. | 1 week |
| intercom-device-id-* | Intercom | Device-level identifier used to deduplicate visitors across browsers. | 9 months |
Crisp
Crisp is a live chat and helpdesk widget. It stores a visitor ID so the conversation survives a page reload.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| crisp-client/session/* | customer_domain | Keeps the chat session so the visitor can continue an ongoing conversation. | 6 months |
Zendesk
The Zendesk Web Widget adds live chat and help centre search. It stores identifiers so a chat can continue across pages.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| __zlcmid | customer_domain | Stores a visitor ID so an ongoing chat conversation is recognised on the next page. | 1 year |
| _zendesk_shared_session | zendesk.com | Maintains the widget session with Zendesk. | Session |
Tawk.to
Tawk.to is a free live chat widget. Paste the property ID and widget ID from your embed code, separated by a slash.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| __tawkuuid | customer_domain | Identifies the visitor so chat history is available on return visits. | 6 months |
| TawkConnectionTime | customer_domain | Records when the widget last connected. | Session |
LiveChat
LiveChat is a hosted chat widget for sales and support teams. It stores session identifiers to keep a conversation alive.
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| __lc_cid | customer_domain | Identifies the visitor so an open chat can be resumed. | 3 years |
| __lc_cst | customer_domain | Stores the chat session state. | 3 years |
Check your own site against this
The scan lists the scripts that run before consent, so you know what you actually need to block.
- Results in about 10 seconds
- No account needed
- Shareable report link
Get your cookie banner live in 5 minutes
Paste one script tag into your site and you're covered. No plugin to install, no code to write, nothing to pay.
- 1 domain
- 5,000 pageviews/mo
- All integrations
- GDPR, CCPA and ePrivacy