What is the aws-waf-token cookie?
Set by AWS WAF (Web Application Firewall) when a site uses its bot-control or challenge features, to record that the visitor's browser passed the challenge.
Our October 2026 scan found it on 47 sites (2% of the 2,450 we scanned), set before any consent.
- Purpose
- Necessary
- Belongs to
- AWS WAF
- Set as
- First-party (under the site's own domain)
- Typical lifetime
- 4 days
Sites that set aws-waf-token before consent
The highest-ranked 30 of 47 sites.
- amazon.com33 tracking companies
- booking.com1 tracking company
- amazon.de1 tracking company
- espn.com0 tracking companies
- amazon.co.jp1 tracking company
- ieee.org2 tracking companies
- amazon.ca1 tracking company
- amazon.in1 tracking company
- amazon.it1 tracking company
- wattpad.com3 tracking companies
Show 20 more sites
- amazon.com.br1 tracking company
- amazon.com.au1 tracking company
- binance.com0 tracking companies
- amazon.com.mx34 tracking companies
- huggingface.co0 tracking companies
- jw.org0 tracking companies
- marktplaats.nl4 tracking companies
- dribbble.com0 tracking companies
- themoviedb.org1 tracking company
- mamastar.jp5 tracking companies
- alphapolis.co.jp9 tracking companies
- amazon.eg1 tracking company
- espn.com.ve0 tracking companies
- playinboss.com1 tracking company
- samsungknox.com1 tracking company
- semanticscholar.org3 tracking companies
- coinmarketcap.com1 tracking company
- howstuffworks.com1 tracking company
- yumpu.com0 tracking companies
- amazon.ae32 tracking companies
How to stop it
Declining non-essential cookies in a site's consent banner should stop optional cookies, though a necessary cookie like this one may still be set. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.
Description written by CookieTosser, for a cookie the Open Cookie Database doesn't cover.
Understanding this page
- How cookie lifetimes work, and why a 13-month _ga matters
What a cookie's "expires" field actually controls, why Google Analytics ships a 2-year default that many sites cut down to 13 months, and how Safari's 7-day cap on script-set cookies changes the picture.
- First-party vs third-party cookies (and why "first-party" still tracks you)
What the distinction actually means technically, why browsers only block one of the two, and how CNAME cloaking, server-side tagging and cookies like _ga let sites keep tracking under their own domain.
- How to block or limit trackers
Browser privacy settings, content blockers, Global Privacy Control and clearing cookies compared honestly — what each one actually stops, what it doesn't, and what it costs you in return.