What is the _hjSession_ cookie?
_hjSession_ is an HTTP cookie set by the Hotjar tracking script, a widely used behavior analytics service (heatmaps, session recordings, on-site surveys). The full cookie name also includes a unique numeric identifier tied to your site's Hotjar account (for example _hjSession_123456).
It appears in the visitor's browser as soon as the Hotjar script loads and runs on the page, typically on first interaction or on page load, unless it is blocked by a consent tool.
What data it stores
The cookie stores a current session identifier, which Hotjar uses to link multiple actions from the same visitor (clicks, mouse movements, scrolling) to a single visit, without mixing them with later visits.
The exact value is a string generated internally by Hotjar and is not publicly documented in detail; the format may vary. Data collected via this cookie is sent to Hotjar's servers (Hotjar Ltd., part of the Contentsquare group), not stored on your own server.
What it is used for
For Hotjar, this cookie allows grouping behavioral events (clicks, scrolling, mouse movement) into a coherent session, which is necessary for generating heatmaps and session recordings.
For the site owner, the resulting aggregated data helps understand how users navigate, where they encounter friction, and which UX elements need improvement — without the session cookie, Hotjar cannot link individual interactions together.
Does it require consent?
In CookieFix's classification, _hjSession_ falls under the statistics category. Since it is used for behavior analysis and is not strictly necessary for the site to function, it requires the visitor's prior consent, per Romania's Law 506/2004 (transposing the ePrivacy Directive) and GDPR's lawful processing principles.
Site owners must list this cookie in their cookie policy, prevent the Hotjar script from loading before consent is obtained, and give visitors a clear option to reject the statistics category.
How to block or delete _hjSession_
A visitor can manually delete or block this cookie from browser settings (Chrome, Firefox, Edge, Safari — usually under "Privacy and security" / "Cookies and site data"), or use tracker-blocking extensions together with third-party cookie blocking, which can also stop the Hotjar script from loading.
For site owners, the correct approach isn't manual deletion but preventing the Hotjar script from loading before consent. A CMP like CookieFix automatically blocks scripts in the statistics category, including Hotjar, until the visitor gives consent, so a refusal means _hjSession_ is never set.
Frequently asked questions
It's a cookie set by Hotjar to identify a current browsing session, used to generate heatmaps and session recordings.
The typical duration is 30 minutes; if the visitor stays inactive longer, the session expires and a new identifier is generated when activity resumes.
Yes, as a statistics/analytics cookie it requires prior consent under GDPR and Law 506/2004, since it isn't strictly necessary for the site to function.
By configuring a CMP that delays loading the Hotjar script until the visitor consents to the statistics category; manually deleting it from a browser is only a temporary, individual-level fix.