What is the csrftoken cookie?
The default cross-site-request-forgery (CSRF) protection cookie set by the Django web framework, used to verify that form submissions come from the same site.
Our October 2026 scan found it on 29 sites (1% of the 2,450 we scanned), set before any consent.
- Purpose
- Necessary
- Belongs to
- Django
- Set as
- First-party (under the site's own domain)
- Typical lifetime
- Session
Sites that set csrftoken before consent
The highest-ranked 29 of 29 sites.
- instagram.com0 tracking companies
- trueconf.net3 tracking companies
- eventbrite.com2 tracking companies
- threads.com1 tracking company
- shopee.com.br0 tracking companies
- shopee.co.id3 tracking companies
- youku.com0 tracking companies
- shopee.ph3 tracking companies
- rutube.ru1 tracking company
- jstor.org2 tracking companies
Show 19 more sites
- ixl.com1 tracking company
- getyourguide.com4 tracking companies
- csdn.net1 tracking company
- toutiao.com1 tracking company
- ipapi.co0 tracking companies
- prezi.com1 tracking company
- eventbrite.co.uk2 tracking companies
- dingtalk.com0 tracking companies
- shopee.vn4 tracking companies
- shopee.sg0 tracking companies
- teacherspayteachers.com5 tracking companies
- shopee.tw3 tracking companies
- shopee.co.th3 tracking companies
- shopee.com.my3 tracking companies
- cwi.nl0 tracking companies
- leetcode.com2 tracking companies
- detik.com13 tracking companies
- terabox.com4 tracking companies
- ufanet.ru2 tracking companies
How to stop it
Declining non-essential cookies in a site's consent banner should stop optional cookies, though a necessary cookie like this one may still be set. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.
Description written by CookieTosser, for a cookie the Open Cookie Database doesn't cover.
Understanding this page
- How cookie lifetimes work, and why a 13-month _ga matters
What a cookie's "expires" field actually controls, why Google Analytics ships a 2-year default that many sites cut down to 13 months, and how Safari's 7-day cap on script-set cookies changes the picture.
- First-party vs third-party cookies (and why "first-party" still tracks you)
What the distinction actually means technically, why browsers only block one of the two, and how CNAME cloaking, server-side tagging and cookies like _ga let sites keep tracking under their own domain.
- How to block or limit trackers
Browser privacy settings, content blockers, Global Privacy Control and clearing cookies compared honestly — what each one actually stops, what it doesn't, and what it costs you in return.