What is the __Secure-1PSID cookie?
The __Secure-1PSID cookie is set by Google on the .google.com domain. It belongs to Google's account authentication cookie family, alongside __Secure-1PSIDTS, SID, SSID, APISID and similar cookies.
It appears on a website when a visitor is signed in to a Google account and the page loads a Google service or widget — for example a 'Sign in with Google' button, an embedded YouTube video, Google Maps, reCAPTCHA, or Google ads. The __Secure- prefix means the browser only sends it over HTTPS connections.
What data it stores
The value is an encrypted, digitally signed string that is not human-readable. It links the browser to the visitor's Google account identity and the time of the last sign-in. Google does not publish the internal value format, and it may vary or change over time.
The cookie is sent to Google's own servers (the *.google.com domains) along with requests to those services. It is not accessible to the host website's own scripts and is never shared with the site itself.
What it is used for
For Google, __Secure-1PSID confirms the signed-in user's identity and keeps the session active across Google services (Gmail, YouTube, Search, Maps, etc.), including when they are embedded on third-party sites.
For the website owner, its presence indicates the page uses a Google service that requires sign-in or shows content personalized for signed-in users. The website itself never gets access to the cookie's contents.
Does it require consent?
Under CookieFix's classification, __Secure-1PSID is strictly necessary — it serves authentication and security, not marketing tracking. Strictly necessary cookies do not require prior consent under Article 5(3) of the ePrivacy Directive (2002/58/EC), but they must still be disclosed in the site's cookie policy.
Site owners should still check the actual context of use: if the embedded Google feature (e.g. ads or remarketing) also relies on related cookies for ad personalization, that component should be classified separately as marketing, with its script blocked until consent is given.
How to block or delete __Secure-1PSID
- Delete or block it from the browser's cookie settings, searching for the
google.comdomain (Chrome, Edge, Firefox: Privacy → Cookies) - Use a private/incognito window to avoid setting it at all
- Deleting it signs the visitor out of their Google account on that browser
For site owners, a consent management platform such as CookieFix can automatically block Google scripts and widgets (login buttons, video embeds, ad tags) from loading until the visitor gives consent — even though this specific cookie, being strictly necessary, doesn't itself need to be blocked.
Frequently asked questions
It's an authentication cookie set by Google on the .google.com domain, used to confirm a signed-in Google account's identity and keep the session active across Google services.
Indirectly yes — it's tied to the user's Google account, but the value itself is encrypted and cannot be read by the site where it appears.
No, since it's classified as strictly necessary (authentication/security) it doesn't require prior consent under ePrivacy/GDPR, but it must be disclosed in the cookie policy.
Through the browser's privacy settings, by clearing cookies for google.com, or by browsing in incognito mode; deleting it signs the visitor out of their Google account on that device.