First-Party Cookies
In short
First-party cookies are set by the domain you are currently visiting. They store things like logins, shopping carts or tracking IDs for that same website.
Also known as: first-party cookie, first party cookie
First-party cookies are small text files set by the domain shown in the address bar. When you visit example.com, only example.com (and its subdomains) can read these cookies. They remember logins, language settings and shopping carts – and in marketing, mainly tracking IDs that connect one person's visits across multiple page views.
How first-party cookies are set
There are two ways:
- Via JavaScript in the browser (
document.cookie): simple, but more restricted by browsers like Safari. - Via an HTTP header from your own domain's server: more robust, because the browser treats them as real server cookies.
The Meta Pixel also sets a first-party cookie on your domain with _fbp, and it stores the fbclid as _fbc.
First-party vs. third-party cookies
Third-party cookies come from a different domain, such as an ad network embedded on many websites. They enable tracking across websites and are blocked by default in Safari and Firefox. First-party cookies still work, but they're limited to your own website.
Example
A user clicks a Meta ad on Monday, looks at the landing page and leaves. On Thursday they come back directly and fill out the form. The lead can only be attributed to the original campaign if a first-party cookie with Monday's ID still exists. If Safari deleted the cookie after 7 days and the user returns after 10 days, the cookie-based connection is gone.
First-party cookies in lead generation
For leads with long decision cycles, a cookie alone often isn't enough. It's more robust to also match the lead to an earlier session via email address or phone number.
That's why LeadMetrics matches leads to sessions not only by session ID but also by email and phone number, up to 90 days back. Depending on your plan, you can also use a custom tracking domain via CNAME so that lead tracking runs on a subdomain of your website.
Common mistakes
- Ignoring consent: In the EU, first-party marketing cookies usually require consent too.
- Assuming long lifetimes: If you plan around a 90-day cookie lifetime, you underestimate how many browsers cut it short.
- Domain changes in the funnel: If the user moves from your website to a funnel on another domain, the cookie doesn't apply there – that's where cross-domain tracking helps.
Ready for better tracking?
Frequently asked questions
Guides on this topic
Related terms
All termsThird-Party Cookies
Third-party cookies are set by a different domain than the one you visit, such as an ad network, and let that domain track users across many websites.
Server-Side Tracking
Server-side tracking sends tracking data to ad and analytics platforms from a server instead of the browser – more robust and under your control.
Client-Side Tracking
Client-side tracking captures user actions with JavaScript directly in the browser and sends them from there to analytics and ad platforms.
Consent Management
Consent management means collecting, storing and managing your website visitors' consent, for example for analytics and marketing cookies.
Cross-Domain Tracking
Cross-domain tracking follows a visitor across multiple domains as one session, for example from your website through a funnel to the checkout.
Conversion API · CAPI
A Conversion API (CAPI) is an interface that sends conversions directly from server to server to ad platforms like Meta or Google, without the browser.