What is the ig_did cookie?
ig_did ("Instagram Device ID") is an HTTP cookie set by Instagram, a platform owned by Meta Platforms Inc. It is issued on the .instagram.com domain, meaning it can be read by Instagram subdomains and Meta scripts loaded within that domain's context.
It commonly appears on a third-party website when that site embeds Instagram content – embedded posts, feed widgets, follow/share buttons, or when a visitor interacts with an Instagram iframe. It may also be set directly when someone visits instagram.com or is logged into the Meta ecosystem.
What data it stores
ig_did stores a unique identifier associated with the visitor's device or browser, generated by Instagram on first interaction. The exact value format is not publicly documented by Meta and may vary; no further technical details are officially confirmed.
Data collected through this identifier is sent to Meta/Instagram servers, where it can be correlated with other Meta cookies (such as those on Facebook) to build a behavioral profile of the device, including across third-party sites embedding Instagram content.
What it is used for
For Meta, ig_did helps recognize the same device across multiple sessions and websites, supporting audience measurement, fraud prevention, and, notably, ad targeting within the Meta Ads network.
For the website owner embedding Instagram content, the cookie provides no direct functional benefit – it primarily serves Meta's tracking interests rather than the host site's own functionality.
Does it require consent?
ig_did is classified as a marketing/tracking cookie. Under the ePrivacy Directive (as transposed and enforced under EU member state law) and GDPR, this type of cookie requires the visitor's explicit prior consent before being placed or read.
Website operators should: list this cookie in their cookie policy, correctly categorize it under marketing/advertising, and ensure the elements that trigger it (Instagram embeds, widgets, Meta pixels) do not load before the visitor gives explicit consent.
How to block or delete ig_did
- Visitors can delete or block ig_did through their browser's privacy/cookie settings (Chrome, Firefox, Safari, Edge), including by blocking third-party cookies or using anti-tracking extensions.
- They can decline the marketing category in a compliant consent banner, which should prevent the Instagram scripts that set this cookie from loading.
For site owners embedding Instagram content, the correct approach is a CMP that automatically blocks the Instagram embed/pixel script until consent is given for the marketing category – exactly the role CookieFix plays when configured on the domain.
Frequently asked questions
It's not technically harmful, but it is a tracking cookie used for advertising purposes, which raises privacy concerns if placed without consent.
Most likely your site embeds an Instagram widget, share button, or embedded post that loads Meta scripts setting this cookie.
Its typical duration is around 1 year from when it's set or last updated, consistent with common Meta cookie practices.
Yes, since it's a marketing/tracking cookie, it requires the visitor's explicit prior consent before being placed.