What is the XSRF-TOKEN cookie?
This cookie is written to help with site security in preventing Cross-Site Request Forgery attacks.
Our October 2026 scan found it on 51 sites (2% of the 2,450 we scanned), set before any consent.
- Purpose
- Necessary
- Set as
- First-party on 94% of sites, third-party on 6%
- Typical lifetime
- Under a day (vendor says: Session)
Sites that set XSRF-TOKEN before consent
The highest-ranked 30 of 51 sites.
- tinyurl.com2 tracking companies
- alibaba.com7 tracking companies
- hostgator.com3 tracking companies
- taobao.com0 tracking companies
- ivi.ru10 tracking companies
- wix.com0 tracking companies
- youku.com0 tracking companies
- flightradar24.com4 tracking companies
- inleed.net0 tracking companies
- battle.net1 tracking company
Show 20 more sites
- ucla.edu5 tracking companies
- mamastar.jp5 tracking companies
- alphapolis.co.jp9 tracking companies
- indown.io3 tracking companies
- packzy.com2 tracking companies
- moe.video3 tracking companies
- mobcup.fm1 tracking company
- elegantthemes.com3 tracking companies
- orcid.org2 tracking companies
- mindbox.ru6 tracking companies
- threema.ch0 tracking companies
- umeng.com1 tracking company
- constantcontact.com3 tracking companies
- laravel.com7 tracking companies
- webgo.de2 tracking companies
- ycombinator.com3 tracking companies
- infomaniak.com0 tracking companies
- upwork.com1 tracking company
- ihc.ru1 tracking company
- dns.com2 tracking companies
How to stop it
Declining non-essential cookies in a site's consent banner should stop optional cookies, though a necessary cookie like this one may still be set. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.
Description from the Open Cookie Database (Apache 2.0).
Understanding this page
- How cookie lifetimes work, and why a 13-month _ga matters
What a cookie's "expires" field actually controls, why Google Analytics ships a 2-year default that many sites cut down to 13 months, and how Safari's 7-day cap on script-set cookies changes the picture.
- First-party vs third-party cookies (and why "first-party" still tracks you)
What the distinction actually means technically, why browsers only block one of the two, and how CNAME cloaking, server-side tagging and cookies like _ga let sites keep tracking under their own domain.
- How to block or limit trackers
Browser privacy settings, content blockers, Global Privacy Control and clearing cookies compared honestly — what each one actually stops, what it doesn't, and what it costs you in return.