What is the __cflb cookie?
When enabling session affinity with Cloudflare Load Balancer, Cloudflare sets a __cflb cookie with a unique value on the first response to the requesting client. Cloudflare routes future requests to the same origin, optimizing network resource usage. In the event of a failover, Cloudflare sets a new __cflb cookie to direct future requests to the failover pool.
Our October 2026 scan found it on 26 sites (1% of the 2,450 we scanned), set before any consent.
- Purpose
- Functional
- Belongs to
- Cloudflare
- Set as
- First-party on 88% of sites, third-party on 12%
- Typical lifetime
- 1 day (vendor says: session)
Sites that set __cflb before consent
The highest-ranked 26 of 26 sites.
- roku.com3 tracking companies
- hcaptcha.com0 tracking companies
- namecheap.com4 tracking companies
- hostgator.com3 tracking companies
- bild.de0 tracking companies
- welt.de0 tracking companies
- deepl.com0 tracking companies
- trendyol.com2 tracking companies
- nexusmods.com5 tracking companies
- stackexchange.com0 tracking companies
Show 16 more sites
- 3bmeteo.com6 tracking companies
- goodreturns.in25 tracking companies
- snaptik.app2 tracking companies
- ojogodobicho.com6 tracking companies
- hostinger.com4 tracking companies
- register.com2 tracking companies
- investing.com6 tracking companies
- ahrefs.com2 tracking companies
- upwork.com1 tracking company
- visa.com3 tracking companies
- easybrain.com2 tracking companies
- domain.com6 tracking companies
- scopus.com2 tracking companies
- dish.com18 tracking companies
- kia.com4 tracking companies
- newegg.com1 tracking company
Related cookies
Other cookies from Cloudflare.
- __cf_bm719 sites
- cf_clearance226 sites
- _cfuvid156 sites
How to stop it
Declining non-essential cookies in a site's consent banner should stop __cflb being set on later visits. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.
Description from the Open Cookie Database (Apache 2.0).
Understanding this page
- How cookie lifetimes work, and why a 13-month _ga matters
What a cookie's "expires" field actually controls, why Google Analytics ships a 2-year default that many sites cut down to 13 months, and how Safari's 7-day cap on script-set cookies changes the picture.
- First-party vs third-party cookies (and why "first-party" still tracks you)
What the distinction actually means technically, why browsers only block one of the two, and how CNAME cloaking, server-side tagging and cookies like _ga let sites keep tracking under their own domain.
- How to block or limit trackers
Browser privacy settings, content blockers, Global Privacy Control and clearing cookies compared honestly — what each one actually stops, what it doesn't, and what it costs you in return.