Skip to content
CookieTosser

What is the _csrf cookie?

This cookie is used to prevent Cross-site request forgery (often abbreviated as CSRF) attacks of the website.

Our October 2026 scan found it on 17 sites (1% of the 2,450 we scanned), set before any consent.

Purpose
Necessary
Belongs to
Stonly
Set as
First-party (under the site's own domain)
Typical lifetime
Session (vendor says: session)

Sites that set _csrf before consent

The highest-ranked 17 of 17 sites.

Show 7 more sites

How to stop it

Declining non-essential cookies in a site's consent banner should stop optional cookies, though a necessary cookie like this one may still be set. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.

Description from the Open Cookie Database (Apache 2.0).

Understanding this page