What is the __Secure-3PAPISID cookie?
__Secure-3PAPISID is an HTTP cookie set by Google on the .google.com domain. It belongs to a group of cookies (together with SAPISID, APISID, HSID, SSID, __Secure-1PAPISID, and others) that Google uses to recognize a browser signed into a Google account and to support advertising services.
It typically appears on a site not because the site is google.com, but when a page loads Google resources such as ads (Google Ads/DoubleClick), embedded Google Maps, a Google sign-in button, or other Google widgets. The „3P” prefix indicates its use in a third-party context, i.e. on domains other than Google's own.
What data it stores
The cookie's value is an identifier tied to the user's Google account, used internally by Google to link the authenticated session to browsing activity on third-party sites. The exact value format is not publicly documented by Google and may vary; it does not directly contain identifying details like a name or email, but functions as a unique identifier.
The collected data is sent to Google's servers and used for personalized advertising, conversion measurement, and potentially combined with other Google services the user is signed into.
What it is used for
For Google, this cookie helps identify signed-in users to deliver relevant ads across its advertising network (Google Ads, AdSense, DoubleClick) and to measure campaign performance across multiple sites.
For the website owner, the presence of this cookie is usually an indirect consequence of embedding Google services (ads, maps, sign-in, embedded YouTube video) and provides no direct functional benefit to the site itself.
Does it require consent?
__Secure-3PAPISID is classified as a marketing/advertising cookie. Under the GDPR and the ePrivacy Directive (transposed in Romania via Law 506/2004), this type of cookie requires the visitor's explicit, prior consent before being set.
- The site owner must declare the cookie in the cookie policy under the „marketing” category.
- The script that triggers it (ads, Google widgets) must be blocked until consent is obtained.
- Visitors must be able to refuse or withdraw consent as easily as they gave it.
How to block or delete __Secure-3PAPISID
A visitor can manually delete or block this cookie via browser settings (Chrome, Firefox, Edge, and Safari all allow deleting cookies per domain) or use tracker-blocking browser extensions. Because it carries the „Secure” attribute, it is only transmitted over HTTPS connections.
For site owners, the correct approach is not manual deletion but preventing the cookie from being set before consent. A CMP platform like the one offered by CookieFix can automatically block the Google scripts that generate this cookie until the visitor grants consent for the marketing category, avoiding unauthorized placement.
Frequently asked questions
It is not a malicious cookie; Google uses it for advertising and authentication purposes. It can, however, raise privacy concerns since it tracks user activity across different sites.
Your site most likely embeds a Google service such as Google Maps, a Google sign-in button, or an embedded YouTube video, which indirectly sets this cookie.
Yes, as a marketing/advertising cookie it requires the visitor's explicit consent under GDPR and ePrivacy rules before it is set.
The typically observed duration is around 2 years, though Google may adjust this value over time.