Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Marketing

guest_id Cookie (X/Twitter) – What It Is and Its Purpose

guest_id is an HTTP cookie set by X (formerly Twitter) to identify visitors, including those without an account, for roughly two years. It is used for tracking and advertising purposes, which is why it is classified as a marketing cookie requiring prior visitor consent.

Name
guest_id
Provider
X (Twitter)
Category
Marketing
Type
HTTP cookie
Lifetime
2 years
Domain / notes
twitter\\.com
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the guest_id cookie?

The guest_id cookie is set by X (formerly Twitter) whenever a webpage loads a „Follow” button, a tweet embed widget, an embedded timeline, or any other element that connects to the twitter.com domain or X's infrastructure.

It appears even when the site visitor has no X account or is not logged in, because its role is to assign a unique identifier to „guest” visitors, allowing X to recognize them on subsequent visits to any site embedding X content.

What data it stores

The cookie value contains a unique identifier generated by X for the visitor session, typically an alphanumeric string prefixed with v1%3A followed by a series of digits. The exact format may vary over time depending on X's implementation.

The data collected through this identifier is sent to X's servers and can be correlated with other X cookies (such as personalization_id or guest_id_marketing) to build a cross-site browsing behavior profile wherever X widgets are used.

What it is used for

For X, guest_id is used to track the behavior of non-logged-in users across the web, measure the effectiveness of its widgets (share buttons, embeds), and feed the platform's targeted advertising and retargeting systems.

For the site owner hosting X content, the cookie provides no direct functional benefit – the site works the same without it – but it appears automatically once X widgets are embedded, which creates a duty to disclose it and obtain consent.

Does it require consent?

Category: marketing (advertising/tracking). As a third-party cookie used for tracking and advertising purposes, guest_id falls under the ePrivacy Directive requirements (implemented in Romania via Law 506/2004) and requires the visitor's prior, explicit consent, meeting the GDPR standard for valid consent (freely given, specific, informed, unambiguous).

  • The site owner must disclose this cookie in the cookie policy, including provider, purpose, and duration.
  • X widgets (buttons, embeds, timelines) should not load before the visitor consents to the marketing category.
  • Refusing consent must be as easy as accepting, and withdrawal must be possible at any time.

How to block or delete guest_id

A visitor can manually delete or block guest_id through browser settings (Chrome, Firefox, Edge, and Safari all allow deleting cookies per domain) or use third-party tracker-blocking extensions. Fully blocking it may prevent X share buttons and embeds from displaying correctly.

For site owners, the recommended approach isn't manual deletion but preventing the cookie from loading in the first place: a CMP like CookieFix can automatically block X scripts and widgets until the visitor explicitly consents to the marketing category, ensuring the legally required order – consent before the cookie is set.

Frequently asked questions

It's an HTTP cookie used by X to identify unique visitors, including those without an account, whenever a page contains X widgets or embedded content.

It has a typical duration of about 2 years from the last time it was set or renewed, unless deleted manually.

Yes, since it's classified as a marketing/tracking cookie, it requires the visitor's prior consent under GDPR and the ePrivacy rules.

By using a CMP that intervenes before X widgets load, so the script setting the cookie only runs after the visitor accepts the marketing category.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.