| Cookie Name |
Duration |
Cookie Type |
Description |
| __Secure-has-sid |
Session |
Essential |
Detects a user’s login state on the client side. Set during login to Aura or LWR Experience. Never set this cookie to HttpOnly. |
| _ga |
2 Years |
Essential |
A third-party cookie that’s used if the site admin chooses to track site users with a Google Analytics tracking ID. |
| {UserId}_spring_KmMlAnyoneDraftArticlesList |
1 Day |
Essential |
In Salesforce Classic, used to configure layout properties for the Draft Articles view in Article Management. |
| {UserId}_spring_KmMlArchivedArticlesList |
1 Day |
Essential |
In Salesforce Classic, used to configure layout properties for 'Archived Articles' in Article Management. |
| {UserId}_spring_KmMlMyDraftArticlesList |
1 Day |
Essential |
In Salesforce Classic, used to configure layout properties for 'Draft Articles' assigned to 'Me' in Article Management. |
| {UserId}_spring_KmMlMyDraftTranslationsList |
1 Day |
Essential |
In Salesforce Classic, used to configure layout properties for 'Draft Translations' in Article Management. |
| {UserId}_spring_KmMlPublishedArticlesList |
1 Day |
Essential |
In Salesforce Classic, used to configure layout properties for 'Published Articles' in Article Management. |
| {UserId}_spring_KmMlPublishedTranslationsList |
1 Day |
Essential |
In Salesforce Classic, used to configure layout properties for 'Published Translations' in Article Management. |
| _sid |
Session |
Essential |
Identifies a Live Agent session. Stores a unique pseudonymous ID for a specific browser session over chat service. |
| 52609e00b7ee307e |
Session |
Essential |
Browser Fingerprint cookie. Used to detect session security problems. |
| 79eb100099b9a8bf |
Session |
Essential |
Browser Fingerprint trigger cookie. Used to detect session security problems. |
| apex__EmailAddress |
1 Year |
Essential |
Caches contact IDs associated with email addresses. |
| BAYEAX_BROWSER |
Expired on Creation |
Essential |
Identify a unique browser subscribed to CometD streaming channels. |
| BrowserId |
1 Year |
Essential |
Used for security protections. Rendered on a subset of Salesforce domains, including .salesforce.com, .force.com, and the domains for Salesforce login pages, Lightning pages, and Experience Cloud sites. |
| clientSrc |
Session |
Essential |
Used for security protections. |
| communityId |
Session |
Essential |
Cookie set to tie the ideas to a specific Experience Cloud site. |
| CookieConsent |
1 Year |
Essential |
Used to apply end-user cookie consent preferences. Stores a Boolean for whether user has consented to the cookie policy options offered by the site. Without this cookie, customers would not be able collect consent from their end users. |
| CookieConsentPolicy |
1 Year |
Essential |
Used to apply end-user cookie consent preferences set by our client-side utility. |
| cookieSettingVerified |
Session |
Essential |
Used to create a popup message telling users that cookies are required. |
| cordovaVersion |
Session |
Essential |
Used for internal diagnostics with mobile applications. |
| csssid |
Session |
Essential |
Used to establish a request context in the correct tenant org. |
| csssid_Client |
Session |
Essential |
Enables user switching. |
| devOverrideCsrfToken |
Session |
Essential |
CSRF Token. |
| dialpadShown |
Session |
Essential |
Used in essential Open CTI functionality to determine the dial pad focus. |
| disco |
Session |
Essential |
Tracks the last user login and active session for bypassing login (For example, OAuth immediate flow). |
| FedAuth |
Session |
Essential |
For the SharePoint connector, used to authenticate to the top-level site in SharePoint. |
| force-proxy-stream |
3 Hours |
Essential |
Ensures that client requests hit the same proxy hosts and are more likely to retrieve content from cache. |
| force-stream |
180 Minutes |
Essential |
Used to redirect server requests for sticky sessions. |
| gTalkCollapsed |
1 Year |
Essential |
Controls whether the sidebar in Salesforce Classic is open or not for a user. |
| idccsrf |
Session |
Essential |
Tracks CrossSiteRequestForgery validation for certain SSO flows. |
| inst |
Session |
Essential |
Used to redirect requests to an instance when bookmarks and hardcoded URLs send requests to a different instance. This type of redirect can happen after an org migration, a split, or after any URL update. |
| language |
Session |
Essential |
Identifies the language for custom components, surveys, and flows, which support multiple languages. Without this cookie, translations for custom features can appear incorrectly. |
| lastActivePage |
Session |
Essential |
Used in essential Open CTI functionality, such as determining if CTI should screen pop the current call object. |
| lastCallObjectId |
Session |
Essential |
Used in essential Open CTI functionality, such as determining if CTI should screen pop the current call object. |
| lastlist |
Session |
Essential |
Used to store the cookie name for the last list URL. |
| liveagent_sid |
Session |
Essential |
Identifies a Live Agent session. Stores a unique pseudonymous ID for a specific browser session over chat service. |
| lloopch_loid |
1 Year |
Essential |
Determines whether to send the user to a specific portal login or an app login. |
| oid |
1 Year |
Essential |
Stores the last logged in org for redirecting requests. Used for logging whether the cookie is present in site and community guest-user requests. |
| pctrk |
1 Year |
Essential |
Used to count unique page views by unauthenticated (guest) users in Experience Cloud sites against a Customer's billing entitlements. |
| PicassoLanguage |
Session |
Essential |
Used to store a user’s language selection for this Experience Builder site. The site doesn’t load without this cookie if the user changes the site’s language. |
| promptTestMod |
30 Days |
Essential |
Stores whether test mode is in effect. This cookie is read-only. |
| renderCtx |
Session |
Essential |
Used to store site parameters in the session for reuse across requests by a single client for functionality and performance reasons. Metadata required for fetching site pages and components based on pageId, schema, viewType, brandingSet, formFactor, and audience targeting. |
| RRetURL |
Session |
Essential |
Used with 'Log in As' to restore the original state. |
| RRetURL2 |
Session |
Essential |
The return URL to redirect to when logging out of a session. |
| RSID |
Session |
Essential |
Session ID and login-as session ID. In this case the cookies are copied to the response and cause the target URL to rebuild appropriately in a proxy situation. The cookies aren't created, examined, or modified. |
| rsid2 |
Session |
Essential |
Stores the encrypted original session ID when switching to a site while switched in as an internal user. |
| sfdc_lv2 |
1 Year |
Essential |
Stores identity confirmation details for Experience Cloud users. If the cookie isn't set or it expires, users must repeat the identity confirmation process the next time that they log in. Identity confirmation requires a verification method such as SMS, an authenticator app, or a security key. |
| sfdc-stream |
3 hours |
Essential |
Used to maintain a sticky (persistent) session on the salesforce.com domain. Makes sure that subsequent streaming requests are forwarded to the same server instance where the streaming subscription request was originally handled. |
| sid |
Session |
Essential |
SessionID. |
| sid_Client |
Session |
Essential |
Used to detect and prevent session tampering. |
| sidebarPinned |
10 Years |
Essential |
Controls the state of the Salesforce Classic sidebar. |
| sitePreview |
Session |
Essential |
Stores the authentication code for previewing the site. Preview mode doesn’t load without this cookie. |
| ssostartpage |
1 Year |
Essential |
Identifies the Identity Provider (IdP) location for SSO; certain service provider initiated SSO requests can fail without this cookie. |
| SUCSP |
Session |
Essential |
Used when the user identity that an administrator is assuming (via Log in to Experience as User) is a Customer Success Portal (CSP) user. |
| SUPRM |
Session |
Essential |
Used when the user identity that an administrator is assuming (via Log in to Experience as) is a Partner Relationship Management (PRM) portal user. |
| useStandbyUrl |
Not Set |
Essential |
Controls how quickly to set the standby URL when loading the softphone. |