What is the JSESSIONID* cookie?
JSESSIONID is a cookie generated by Servlet containers and used for session management in J2EE web applications for HTTP protocol. If a Web server is using a cookie for session management, it creates and sends JSESSIONID cookie to the client and then the client sends it back to the server in subsequent HTTP requests. JSESSIONID is a platform session cookie and is used by sites with JavaServer Pages (JSP). The cookie is used to maintain an anonymous user session by the server.
Our October 2026 scan found it on 66 sites (3% of the 2,450 we scanned), set before any consent.
- Purpose
- Functional
- Belongs to
- J2EE
- Set as
- First-party on 82% of sites, third-party on 18%
- Typical lifetime
- Session (vendor says: session)
- Name
- A family of cookies: the part after JSESSIONID varies by site or account.
Sites that set JSESSIONID* before consent
The highest-ranked 30 of 66 sites.
- linkedin.com0 tracking companies
- duckdns.org2 tracking companies
- namecheap.com4 tracking companies
- ok.ru6 tracking companies
- alibaba.com7 tracking companies
- hostgator.com3 tracking companies
- bloomberg.com4 tracking companies
- anydesk.com2 tracking companies
- iso.org2 tracking companies
- globalsign.com3 tracking companies
Show 20 more sites
- buydomains.com2 tracking companies
- zillow.com4 tracking companies
- rakuten.com3 tracking companies
- otto.de0 tracking companies
- change.org6 tracking companies
- ancestry.com5 tracking companies
- costco.com3 tracking companies
- suumo.jp11 tracking companies
- jalan.net27 tracking companies
- elsevier.com3 tracking companies
- indianrail.gov.in10 tracking companies
- oddspark.com7 tracking companies
- ecnavi.jp7 tracking companies
- ixl.com1 tracking company
- umeng.com1 tracking company
- constantcontact.com3 tracking companies
- made-in-china.com3 tracking companies
- 1688.com0 tracking companies
- www.gov.cn0 tracking companies
- abcnews.com11 tracking companies
How to stop it
Declining non-essential cookies in a site's consent banner should stop JSESSIONID* being set on later visits. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.
Description from the Open Cookie Database (Apache 2.0).
Understanding this page
- How cookie lifetimes work, and why a 13-month _ga matters
What a cookie's "expires" field actually controls, why Google Analytics ships a 2-year default that many sites cut down to 13 months, and how Safari's 7-day cap on script-set cookies changes the picture.
- First-party vs third-party cookies (and why "first-party" still tracks you)
What the distinction actually means technically, why browsers only block one of the two, and how CNAME cloaking, server-side tagging and cookies like _ga let sites keep tracking under their own domain.
- How to block or limit trackers
Browser privacy settings, content blockers, Global Privacy Control and clearing cookies compared honestly — what each one actually stops, what it doesn't, and what it costs you in return.