Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Preferences

__io Cookie (OneSignal) – What It Is and What It Does

__io is an entry stored by OneSignal in the browser's localStorage, used to recognize a visitor who has already interacted with the OneSignal push notification widget on a site. It is persistent, and while not a classic HTTP cookie, it is treated similarly under ePrivacy rules because it stores information on the user's device.

Name
__io
Provider
Onesignal
Category
Preferences
Type
localStorage
Lifetime
Persistent
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the __io cookie?

__io is a value written by the OneSignal script (the web push notification SDK) directly into the browser's localStorage, rather than as a regular HTTP cookie. It appears on a site as soon as the OneSignal SDK loads, regardless of whether the visitor accepts push notifications or not.

OneSignal is a third-party service many sites use to send push notifications and in-app messages, and to manage user segmentation for marketing and retention.

What data it stores

The __io entry typically holds a technical identifier tied to the session or instance of the OneSignal widget on that device, used to coordinate the SDK's internal workings (for example, recognizing the browser across page reloads). The exact value format is not publicly documented by OneSignal and may vary by SDK version.

The data is not sent as an HTTP cookie with every server request; instead it's read by the OneSignal script and may be transmitted to OneSignal's servers when the SDK communicates with its infrastructure (for example, when registering for notifications).

What it is used for

For OneSignal, __io helps maintain the widget's internal state — for instance, whether the user has already been "seen" by the SDK, what display preferences apply, or how synchronization between script instances on the same page is managed.

For the site owner, this entry is a technical prerequisite for the OneSignal push notification or messaging widget to function correctly.

Does it require consent?

CookieFix classifies __io under the preferences (functional) category. Although it is stored in localStorage rather than as a classic HTTP cookie, the ePrivacy Directive and its national implementation (in Romania, Law 506/2004) treat any storage of or access to information on a user's device, regardless of the underlying technology, under the same rules as cookies.

  • Being functional/preferences rather than strictly necessary for a service explicitly requested by the visitor, it requires prior consent under GDPR and ePrivacy.
  • The site owner must declare __io in the cookie policy, including the provider (OneSignal), purpose, and duration.
  • The OneSignal script should only load after the visitor has given explicit consent for the preferences category.

How to block or delete __io

A visitor can manually clear the __io entry from the browser's local storage settings for that domain, or use a private browsing session.

Site owners need to make sure the OneSignal script doesn't run before consent is obtained. A consent management platform (CMP) like CookieFix can automatically block the OneSignal script from loading until the visitor consents to the preferences category, preventing __io from being set prematurely.

Frequently asked questions

It's a localStorage entry, not a classic HTTP cookie, but it's treated the same way legally under ePrivacy and GDPR.

Yes — classified as preferences/functional, it requires prior consent before being set.

It's persistent, meaning it stays stored long-term, with no fixed expiration date publicly documented by OneSignal.

OneSignal may recreate the entry the next time its script loads on the site, and some notification features may be reinitialized.

Updated 8 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.