Contact

What is Third-Party Cookie?

Definition

A third-party cookie is set not by the site the user is visiting but by another domain embedded in the page, such as an ad server, a social button, a video player or a chat widget. Because the same cookie can be read on many sites, it lets that third party link a user's browsing across sites for ad targeting and measurement. Safari and Firefox block or partition such cookies by default; Chrome leaves the choice to users.

Also known as: 3rd-party cookie, third party cookie, cross-site cookie, 3P cookie, tracking cookie

Flow showing a tag embedded on different sites using one third-party cookie ID to build a cross-site profile

Many sites inside one page

When you open a news article, the browser fetches resources not only from the news site but also from an ad server, a video platform, a social button and a chat widget. Each of those domains can set cookies in its responses, and because none of them is the site in the address bar, those are third-party cookies. The same cookie is sent back whenever that domain is embedded on any other site, so a single ID can stitch together a user's visits across dozens of sites into one profile. That is the technical basis of cross-site tracking.

In current browsers a cookie can only be sent in a cross-site context if it is marked SameSite=None, which in turn requires the Secure attribute:

Set-Cookie: widget_session=a81f; SameSite=None; Secure; Path=/

The other values of the attribute, and its role against CSRF, are covered under SameSite.

Where browsers stand

BrowserDefault behaviour
SafariIntelligent Tracking Prevention blocks third-party cookies by default; access can be granted only through mechanisms such as the Storage Access API.
FirefoxWith Enhanced Tracking Protection on, Total Cookie Protection gives each third party a separate cookie jar per site, so one cookie cannot bridge sites.
ChromeDoes not block them by default; blocks them in Incognito or when the user opts to in settings.

Chrome's plans changed several times. After abandoning its plan to phase out third-party cookies, Google announced in April 2025 that it would not show a standalone choice prompt either; the choice stays in Chrome's Privacy and Security settings. In October 2025 it retired most Privacy Sandbox technologies, including Topics, Protected Audience and Attribution Reporting, while CHIPS and FedCM continue. Google's announcement has the details.

What breaks and what replaces it

Blocking affects more than advertising. Typical casualties are login or payment steps running in an iframe on another domain, embedded chat and comment widgets that need to remember the user, retargeting, and cross-site attribution. The options that remain:

  • CHIPS (the Partitioned attribute): an embedded tool can keep a cookie, but in a separate jar for each top-level site, so it cannot track across sites.
  • Storage Access API: embedded content asks for access to its own cookies, gated by user interaction and permission.
  • FedCM: handles “Sign in with…” flows without relying on third-party cookies.
  • First-party data and server-side measurement: measuring through your own domain, within consent rules.

Who answers for them legally

Turkey's data protection authority states in its cookie guidance that when third-party cookies are placed on a page, both the site owner and the third party must inform users and obtain consent, and that in practice users direct complaints at the site they know. Behavioural advertising and social plugin tracking cookies require consent, and social plugins should not set third-party cookies for non-members by default. EU rules lead to a similar result. Keeping these cookies from loading before a choice is made is the core job of cookie consent; for the counterpart concept see first-party cookie.

Related terms

← Back to the glossary