What is the gig_canary cookie?
Indicates whether the client is using the canary version of the WebSDK.
Our October 2026 scan found it on 6 sites (0% of the 2,450 we scanned), set before any consent.
- Purpose
- Functional
- Belongs to
- SAP
- Set as
- Third-party (under another company's domain)
- Typical lifetime
- Under a day (vendor says: 12 months) — shorter than the vendor documents
Sites that set gig_canary before consent
The highest-ranked 6 of 6 sites.
- cambridge.org2 tracking companies
- repubblica.it5 tracking companies
- rtve.es5 tracking companies
- kpmg.com1 tracking company
- rte.ie1 tracking company
- lastampa.it6 tracking companies
Related cookies
Other cookies from SAP.
- gig_bootstrap_*8 sites
- gmid8 sites
- hasGmid8 sites
- ucid8 sites
- ua_*4 sites
How to stop it
Declining non-essential cookies in a site's consent banner should stop gig_canary being set on later visits. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.
Description from the Open Cookie Database (Apache 2.0).
Understanding this page
- How cookie lifetimes work, and why a 13-month _ga matters
What a cookie's "expires" field actually controls, why Google Analytics ships a 2-year default that many sites cut down to 13 months, and how Safari's 7-day cap on script-set cookies changes the picture.
- First-party vs third-party cookies (and why "first-party" still tracks you)
What the distinction actually means technically, why browsers only block one of the two, and how CNAME cloaking, server-side tagging and cookies like _ga let sites keep tracking under their own domain.
- How to block or limit trackers
Browser privacy settings, content blockers, Global Privacy Control and clearing cookies compared honestly — what each one actually stops, what it doesn't, and what it costs you in return.