Skip to content
CookieTosser

What is the __RequestVerificationToken* cookie?

This is an anti-forgery cookie set by web applications built using ASP.NET MVC technologies. It is designed to stop unauthorised posting of content to a website, known as Cross-Site Request Forgery.

Our October 2026 scan found it on 3 sites (0% of the 2,450 we scanned), set before any consent.

Purpose
Functional
Belongs to
Microsoft
Set as
First-party (under the site's own domain)
Typical lifetime
Session (vendor says: session)
Name
A family of cookies: the part after __RequestVerificationToken varies by site or account.

Sites that set __RequestVerificationToken* before consent

The highest-ranked 3 of 3 sites.

Related cookies

Other cookies from Microsoft.

How to stop it

Declining non-essential cookies in a site's consent banner should stop __RequestVerificationToken* being set on later visits. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.

Description from the Open Cookie Database (Apache 2.0).

Understanding this page