ScanCookies

← All guides

First-party vs third-party cookies

The difference comes down to who sets the cookie: the website you are visiting, or some other company embedded in its pages.

First-party cookies

A first-party cookie is set by the domain in your address bar. If you are on example.com, a cookie from example.com is first-party. These power logins, carts and preferences, and only example.com can read them. Most strictly necessary and functional cookies are first-party.

Third-party cookies

A third-party cookie is set by a different domain whose code is embedded in the page — an ad network, a social widget, an analytics provider. Because that same third party appears on thousands of sites, it can recognise your browser across all of them. This is the classic mechanism behind cross-site ad tracking.

Why third-party cookies are disappearing

Safari and Firefox already block third-party cookies by default, and the industry has spent years debating Chrome's approach. The direction of travel is clear: third-party cookies are being phased out in favour of first-party data and server-side tracking. Consent law still applies to those replacements, so a banner is not optional just because the cookies moved first-party.

Cookies like this

  • PHPSESSID — PHP (generic)
  • fr — Meta (Facebook)
  • IDE — Google DoubleClick
See it on a real site

Scan any website and we'll list every cookie it sets — categorised, with the ones that load before consent flagged.

Scan a website →

Related guides

General information to help you understand cookies — not legal advice.