Skip to content
CookieTosser

What is the aws-waf-token cookie?

Set by AWS WAF (Web Application Firewall) when a site uses its bot-control or challenge features, to record that the visitor's browser passed the challenge.

Our October 2026 scan found it on 47 sites (2% of the 2,450 we scanned), set before any consent.

Purpose
Necessary
Belongs to
AWS WAF
Set as
First-party (under the site's own domain)
Typical lifetime
4 days

Sites that set aws-waf-token before consent

The highest-ranked 30 of 47 sites.

Show 20 more sites

How to stop it

Declining non-essential cookies in a site's consent banner should stop optional cookies, though a necessary cookie like this one may still be set. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.

Description written by CookieTosser, for a cookie the Open Cookie Database doesn't cover.

Understanding this page