Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

_twitter_sess Cookie by X (Twitter): What It Is & Does

_twitter_sess is a session cookie set by X (Twitter) through its embedded widgets, such as share buttons, embedded tweets, or timelines. It is treated as strictly necessary since it supports the user's session on the X platform while interacting with embedded content.

Name
_twitter_sess
Provider
X (Twitter)
Category
Necessary
Type
HTTP cookie
Lifetime
Session
Domain / notes
.twitter.com
Consent
No, but it must be listed in the cookie policy

What is the _twitter_sess cookie?

_twitter_sess is an HTTP cookie set by X (formerly Twitter) on the .twitter.com domain when a visitor interacts with X content embedded on a third-party website, such as a "Share on X" button, an embedded tweet, or a timeline widget.

The cookie typically appears when the official X widgets script (platform.twitter.com) loads, or when a visitor clicks a share button, rather than on simple page load if the widget is lazy-loaded or conditional.

What data it stores

The cookie holds information tied to a temporary session on X's infrastructure, used to maintain authenticated or anonymous session state while the visitor interacts with the embedded widget. The exact value format is not publicly documented by X and may vary.

As a session cookie, it is sent to X's servers with each request to the .twitter.com domain and is automatically deleted when the browser is closed.

What it is used for

For X, this cookie supports correct session handling within its widgets (displaying tweets, share buttons, timelines) when embedded on third-party sites.

For the website operator, this cookie's presence is simply a side effect of embedding X elements (a share button, an embedded tweet) — it provides no direct analytics or marketing benefit to the site itself and is purely technical, tied to the provider.

Does it require consent?

CookieFix classifies _twitter_sess as strictly necessary, since it supports basic session functionality on X's infrastructure while the visitor interacts with the embedded widget.

  • Strictly necessary cookies do not require prior consent under Article 5(3) of the ePrivacy Directive (implemented in Romania via Law 506/2004), but must be transparently disclosed in the cookie policy.
  • The site operator should list this cookie and its provider (X/Twitter) in the cookie policy, including its purpose and duration.
  • If the X widget later sets additional cookies for cross-site tracking or advertising, those (not this one) may require separate consent.

How to block or delete _twitter_sess

A visitor can delete or block this cookie from browser settings (Chrome, Firefox, Edge, Safari) under per-site cookie management, by searching for the twitter.com domain. Blocking third-party cookies generally in the browser also prevents it from being set.

A site operator using a CMP such as CookieFix can automatically block the X widgets script (platform.twitter.com) from loading until the visitor gives consent, preventing _twitter_sess from being set before acceptance.

Frequently asked questions

It's a session cookie set by X (Twitter) on the .twitter.com domain, used to support embedded X widgets on other websites, such as embedded tweets or share buttons.

Since it's classified as strictly necessary, it doesn't require prior consent under ePrivacy, but it must be disclosed in the site's cookie policy.

It's a session cookie, so it's automatically deleted when the browser is closed and has no fixed expiration date.

You can use a CMP like CookieFix to automatically block the X widgets script until consent is given, or remove embedded X elements entirely.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.