What is the ASP.NET_SessionId cookie?
ASP.Net_SessionId is a cookie which is used to identify the users session on the server. The session being an area on the server which can be used to store session state in between http requests.
Our October 2026 scan found it on 23 sites (1% of the 2,450 we scanned), set before any consent.
- Purpose
- Functional
- Belongs to
- ASP.net
- Set as
- First-party on 96% of sites, third-party on 4%
- Typical lifetime
- Session (vendor says: session)
Sites that set ASP.NET_SessionId before consent
The highest-ranked 23 of 23 sites.
- asus.com1 tracking company
- agoda.com0 tracking companies
- apa.org4 tracking companies
- fabswingers.com0 tracking companies
- fabguys.com0 tracking companies
- uchicago.edu5 tracking companies
- euronews.com12 tracking companies
- globenewswire.com2 tracking companies
- gallup.com1 tracking company
- adp.com6 tracking companies
Show 13 more sites
- powerbi.com1 tracking company
- allstate.com2 tracking companies
- heart.org5 tracking companies
- mimecast.com2 tracking companies
- dmca.com2 tracking companies
- next.co.uk2 tracking companies
- carnival.com3 tracking companies
- forticloud.com0 tracking companies
- yallakora.com5 tracking companies
- nirvam.it2 tracking companies
- admissions.nic.in1 tracking company
- ct.gov5 tracking companies
- worldtimeserver.com3 tracking companies
Related cookies
Other cookies from ASP.net.
- MUID38 sites
- _uetsid22 sites
- _uetvid21 sites
- MR16 sites
- ai_session13 sites
How to stop it
Declining non-essential cookies in a site's consent banner should stop ASP.NET_SessionId being set on later visits. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.
Description from the Open Cookie Database (Apache 2.0).
Understanding this page
- How cookie lifetimes work, and why a 13-month _ga matters
What a cookie's "expires" field actually controls, why Google Analytics ships a 2-year default that many sites cut down to 13 months, and how Safari's 7-day cap on script-set cookies changes the picture.
- First-party vs third-party cookies (and why "first-party" still tracks you)
What the distinction actually means technically, why browsers only block one of the two, and how CNAME cloaking, server-side tagging and cookies like _ga let sites keep tracking under their own domain.
- How to block or limit trackers
Browser privacy settings, content blockers, Global Privacy Control and clearing cookies compared honestly — what each one actually stops, what it doesn't, and what it costs you in return.