Skip to content
CookieTosser

What is the JSESSIONID* cookie?

JSESSIONID is a cookie generated by Servlet containers and used for session management in J2EE web applications for HTTP protocol. If a Web server is using a cookie for session management, it creates and sends JSESSIONID cookie to the client and then the client sends it back to the server in subsequent HTTP requests. JSESSIONID is a platform session cookie and is used by sites with JavaServer Pages (JSP). The cookie is used to maintain an anonymous user session by the server.

Our October 2026 scan found it on 66 sites (3% of the 2,450 we scanned), set before any consent.

Purpose
Functional
Belongs to
J2EE
Set as
First-party on 82% of sites, third-party on 18%
Typical lifetime
Session (vendor says: session)
Name
A family of cookies: the part after JSESSIONID varies by site or account.

Sites that set JSESSIONID* before consent

The highest-ranked 30 of 66 sites.

Show 20 more sites

How to stop it

Declining non-essential cookies in a site's consent banner should stop JSESSIONID* being set on later visits. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.

Description from the Open Cookie Database (Apache 2.0).

Understanding this page