What is the __cfruid cookie?
__cfruid is an HTTP cookie generated by Cloudflare, the CDN, security, and web traffic optimization provider used by a very large number of websites. It is not set directly by the site owner, but by Cloudflare's infrastructure sitting in front of the website.
It appears automatically when a site uses certain Cloudflare services, such as rate limiting or other security modules that need to distinguish legitimate traffic from automated traffic. The cookie is created on the visitor's first interaction with the site and lasts for the duration of the browser session.
What data it stores
Cloudflare does not publish the exact format of the value stored in __cfruid, and it may vary; according to the provider's documentation, the cookie contains an internal identifier used to distinguish requests coming from a genuine user from those coming from bots.
The data is sent to Cloudflare's servers, which process it to decide how to handle requests from a security standpoint. Cloudflare states that this cookie does not correspond to any individual user identifier used for marketing purposes.
What it is used for
The main purpose of __cfruid is to help Cloudflare identify individual requests within its security services, particularly when a site uses features such as rate limiting or protection against automated attacks.
For the site owner, this cookie indirectly contributes to the site running smoothly, by filtering unwanted traffic and keeping Cloudflare's active security services on the domain functioning correctly.
Does it require consent?
In CookieFix's classification, __cfruid falls under strictly necessary cookies, since it supports security functions essential to the correct operation of the infrastructure serving the website.
- Strictly necessary cookies do not require prior visitor consent, in line with ePrivacy Directive requirements (transposed in Romania via Law 506/2004) and ANSPDCP guidance.
- The site owner should still list this cookie in the cookie policy, describing its purpose and duration.
- If a site uses additional Cloudflare modules for analytics or marketing purposes, those must be assessed separately, as they may require consent.
How to block or delete __cfruid
A visitor can delete or block __cfruid from the browser's cookie settings, or use private/incognito browsing. Blocking this cookie may affect the Cloudflare security features of the visited site, particularly if the site relies on rate limiting.
Because it is classified as strictly necessary, __cfruid should not be automatically blocked by a CMP before consent. A platform such as CookieFix can still correctly list it in the cookie policy and automatically block other scripts from categories that require consent, until the visitor gives their agreement.
Frequently asked questions
No, it is classified as strictly necessary because it supports Cloudflare's security functions, so it does not require prior consent under ePrivacy/GDPR, but it must be disclosed in the cookie policy.
It is a session cookie, meaning it typically expires when the browser is closed.
Cloudflare's security features, such as rate limiting, may work less effectively for that session, but general access to the site should not be blocked.
No, according to Cloudflare this cookie serves a technical role related to security and traffic management, not advertising tracking.