What is the __Secure-ROLLOUT_TOKEN cookie?
__Secure-ROLLOUT_TOKEN is an HTTP cookie set by YouTube, a service owned by Google LLC, on the .youtube.com domain. It appears when a visitor loads an embedded YouTube video on a website, or visits youtube.com directly.
The cookie is part of Google's internal mechanism for gradual feature rollouts, ensuring a user is consistently shown the same variant of the video player or interface across multiple visits.
What data it stores
The cookie stores an internal technical token that Google uses to determine which rollout variant (a gradually deployed feature version) a given browser is assigned to. Google does not publicly document the exact value format.
The data is sent to YouTube/Google servers on every request to the .youtube.com domain, including when a video is played through an iframe embedded on a third-party site.
What it is used for
For Google, this cookie helps manage the staged rollout of changes to the video player or YouTube interface, allowing controlled testing and release of features to subsets of users.
For the site owner embedding YouTube videos, the cookie serves no direct purpose — it belongs to Google's infrastructure but appears in the site's context because of the video embed.
Does it require consent?
The __Secure- prefix means the cookie can only be transmitted over HTTPS connections. CookieFix classifies it as strictly necessary, since it supports the technical operation of the video player rather than profiling or advertising.
Strictly necessary cookies do not require prior consent under the ePrivacy Directive (as transposed into Romanian law via Law 506/2004), but they must still be disclosed in the site's cookie policy. Using YouTube's privacy-enhanced mode (youtube-nocookie.com) or a click-to-play thumbnail can avoid or reduce exposure to this cookie.
How to block or delete __Secure-ROLLOUT_TOKEN
A visitor can delete or block this cookie from their browser settings (Chrome, Firefox, Edge, Safari — cookies and site data section), either globally or specifically for the youtube.com domain.
- A site owner can delay loading YouTube embeds until consent is given, using a click-to-play thumbnail instead of a direct iframe.
- A consent management platform like CookieFix can automatically block YouTube scripts and iframes until the visitor consents to the relevant category, reducing compliance risk.
Frequently asked questions
It's a technical cookie set by YouTube/Google to manage the staged rollout of video player features, not for advertising purposes.
CookieFix classifies it as strictly necessary, so it doesn't require prior consent, but it should still be listed in the site's cookie policy.
It typically lasts around 6 months before it expires automatically.
You can use the youtube-nocookie.com domain for embeds, or delay loading the video until a visitor clicks to play or gives consent.