What is the APISID cookie?
APISID is an HTTP cookie set by Google on the .google.com domain when a user is signed into a Google account and interacts with Google services or with third-party sites loading Google resources (for example Google Maps, embedded YouTube videos, share buttons, or ads served through Google Ads/DoubleClick).
It is not set directly by the website owner but by Google scripts and widgets embedded on the page. It typically appears as soon as the browser makes a request to a Google domain while the user is logged into their Google account.
What data it stores
APISID stores an encrypted/hashed value, unique to each user and Google authentication session, used to verify account identity and to help coordinate behavioral and preference signals across Google services.
The exact value format is not publicly documented in detail by Google and varies between users; the cookie is sent to Google domains (google.com and related subdomains), not to the third-party site where it is observed.
What it is used for
For Google, APISID helps recognize signed-in users and correlate their activity across various Google services, supporting the creation of interest profiles used for personalized advertising through the Google Ads network.
For the website owner, this cookie has no direct function – it appears as a side effect of embedding Google services (widgets, maps, video, ads) and indirectly contributes to the effectiveness of behaviorally targeted advertising campaigns.
Does it require consent?
APISID is classified as a marketing cookie (advertising/tracking) and, under the GDPR and the ePrivacy Directive (2002/58/EC, transposed in Romania via Law 506/2004), requires prior user consent before being set, since it is not strictly necessary for the site to function.
- The site owner must disclose it in the cookie policy, listing provider, category, and duration.
- Google scripts that generate it must be blocked until explicit consent for the marketing category is obtained.
- Data protection authorities (in Romania, ANSPDCP) can sanction placing such cookies without valid consent.
How to block or delete APISID
A visitor can manually delete or block APISID from browser settings (Chrome, Firefox, Edge, Safari – cookies and site data section), which effectively signs them out of their Google account on that device, or use private/incognito browsing.
At the site level, Google scripts that set APISID (widgets, embeds, ads) should only load after consent is given. A consent management platform such as CookieFix can automatically block these scripts until the user accepts the marketing category, preventing premature placement.
Frequently asked questions
It is not malicious, but it is part of Google's cross-service tracking infrastructure for personalized advertising, meaning it can contribute to profiling browsing behavior.
Deleting it signs you out of your Google account on that browser; it will be recreated automatically the next time you log in.
It usually appears because of third-party Google widgets or scripts (Maps, YouTube, ads) loaded on the page, not because the site sets it directly.
Yes, as a marketing cookie set by Google, it should be disclosed with provider, purpose, and approximate duration in the site's cookie policy.