---
title: "What is a first-party cookie? Example | Product Metrics"
description: "A first-party cookie is set by the site a visitor is on, such as your shop, not by another domain. See an example and how browser limits affect shop tracking."
canonical: "https://www.productmetrics.io/glossary/first-party-cookie"
pageType: article
language: en
publisher: "Product Metrics"
author: "Berend Vrakking"
datePublished: 2026-10-07
dateModified: 2026-10-07
---

> Content index: https://www.productmetrics.io/llms.txt

# First-party cookie

A first-party cookie is a cookie set by the site the visitor is on, such as your shop, rather than by another domain.

## Example

Three cookies on one visit to shop.example:

| Cookie | Set by | Type |
| --- | --- | --- |
| cart_id | shop.example | First-party |
| language | shop.example | First-party |
| ad_network_id | adnetwork.example | Third-party |

The visitor is on shop.example. The first two cookies come from that same domain, and the third comes from another one. Illustrative data.

## For one product, and for an account

Because your shop’s own domain stores it, a first-party cookie can carry a value such as a click ID from the landing page all the way to the purchase. A third-party cookie belongs to someone else’s domain, such as an ad network’s.

Being first-party does not make a cookie permanent. Browsers limit cookies, and how hard depends on how the cookie was created. WebKit says Safari’s Intelligent Tracking Prevention deletes all cookies created in JavaScript, and all other script-writeable storage, after 7 days of no user interaction with the website. For cookies set in an HTTP response, it states a 7-day cap only for requests it detects as third-party CNAME cloaking or IP address cloaking.

Full Signal Tracking’s first-party cookie lasts 30 days when it is served from your own origin. Full Signal Tracking sends purchases from a unique endpoint on your own domain and gets through every adblocker, and it reads the visitor’s consent choice before sending anything: first-party does not mean consent-free.

## Common mistake

Assuming a first-party cookie is exempt from browser limits. WebKit’s 7-day rule applies to cookies created in JavaScript, whichever domain they belong to.

## Questions

### What is the difference between a first-party and a third-party cookie?

A first-party cookie comes from the same site as the page in the address bar. A third-party cookie comes from a different domain. The difference is who set the cookie, not what it holds.

### Can you give an example of a first-party cookie?

A shop’s cart cookie is one. The shop’s own domain sets it so the basket stays the same between pages. A language choice saved by the same domain is another.

### What is a third-party cookie?

A cookie set by a domain other than the one the visitor is on. A page only has to embed an image or a frame from another site for that site to set one.

## Sources

- [WebKit: Tracking Prevention](https://webkit.org/tracking-prevention/)
- [MDN: Third-party cookies](https://developer.mozilla.org/en-US/docs/Web/Privacy/Guides/Third-party_cookies)

## Keep reading

- [GCLID](https://www.productmetrics.io/glossary/gclid): The click ID Google Ads adds to the landing page URL.
- [Full Signal Tracking](https://www.productmetrics.io/server-side-tracking): See how purchases reach Google Ads from your own domain.
- [Ad blocker test](https://www.productmetrics.io/ad-blocker-conversion-tracking): See what six blockers stop, tested in real browsers.
- [Google tag gateway vs server-side tagging](https://www.productmetrics.io/blog/google-tag-gateway-vs-server-side-tagging): Two ways to serve tags and cookies from your own domain.
- [Enhanced conversions vs server-side tracking](https://www.productmetrics.io/blog/enhanced-conversions-vs-server-side-tracking): What each method recovers when cookies are blocked or expire.

---

Written by Berend Vrakking, founder of Product Metrics. Last updated 2026-10-07.

HTML version: https://www.productmetrics.io/glossary/first-party-cookie
