Skip to content
CookieTosser

What is the csrftoken cookie?

The default cross-site-request-forgery (CSRF) protection cookie set by the Django web framework, used to verify that form submissions come from the same site.

Our October 2026 scan found it on 29 sites (1% of the 2,450 we scanned), set before any consent.

Purpose
Necessary
Belongs to
Django
Set as
First-party (under the site's own domain)
Typical lifetime
Session

Sites that set csrftoken before consent

The highest-ranked 29 of 29 sites.

Show 19 more sites

How to stop it

Declining non-essential cookies in a site's consent banner should stop optional cookies, though a necessary cookie like this one may still be set. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.

Description written by CookieTosser, for a cookie the Open Cookie Database doesn't cover.

Understanding this page