Skip to content
CookieTosser

What is the XSRF-TOKEN cookie?

This cookie is written to help with site security in preventing Cross-Site Request Forgery attacks.

Our October 2026 scan found it on 51 sites (2% of the 2,450 we scanned), set before any consent.

Purpose
Necessary
Set as
First-party on 94% of sites, third-party on 6%
Typical lifetime
Under a day (vendor says: Session)

Sites that set XSRF-TOKEN before consent

The highest-ranked 30 of 51 sites.

Show 20 more sites

How to stop it

Declining non-essential cookies in a site's consent banner should stop optional cookies, though a necessary cookie like this one may still be set. Blocking third-party cookies in your browser settings stops the third-party kind everywhere, and clearing cookies for a site removes any it already set.

Description from the Open Cookie Database (Apache 2.0).

Understanding this page