What is the mage-messages cookie?
mage-messages is a first-party cookie automatically set by the Magento platform on online stores built with this system. It is part of Magento's internal mechanism for handling session notifications, often referred to as "flash messages".
The cookie typically appears when a visitor triggers an action that generates a system message: adding a product to the cart, submitting a form, a failed login attempt, or completing an order. Magento temporarily stores the message so it can be shown after the visitor is redirected to a new page.
What data it stores
The cookie stores an identifier or the content of the system messages generated by Magento (success, error, or warning type), needed to display them correctly on the next page loaded by the visitor.
The exact value format may vary depending on the Magento version and store configuration. The data is stored in the visitor's browser and is read only by the server hosting the Magento store, without being shared with third parties.
What it is used for
The cookie's purpose is strictly functional: it allows Magento to pass status messages between pages, in a flow typical of web applications that redirect the user after an action (for example, adding a product to the cart followed by a return to the product page).
Without this cookie, the store might lose confirmation or error messages relevant to the user, affecting the shopping experience, though the site's core functionality generally remains unaffected.
Does it require consent?
mage-messages is classified as a strictly necessary cookie, since it directly supports internal mechanisms of the e-commerce platform, with no analytics, advertising, or behavioral tracking purpose.
- Under GDPR and the ePrivacy Directive (transposed in Romania via Law 506/2004), strictly necessary cookies do not require prior visitor consent.
- The site owner must still disclose it in the cookie policy, along with its actual purpose and duration.
- If the store uses additional Magento modules that extend this cookie for other purposes (e.g. advanced personalization), reclassification may be required.
How to block or delete mage-messages
Visitors can delete or block this cookie at any time from their browser settings (Chrome, Firefox, Edge, Safari), under the cookie management section for a given site. Blocking it may prevent confirmation or error messages in the store from displaying correctly.
Because it is strictly necessary, site owners do not need to block it pending consent through a CMP like CookieFix, which instead handles automatic blocking of scripts in the statistics, marketing, and preferences categories until the visitor makes a choice.
Frequently asked questions
No, it is a strictly necessary cookie used to display system messages in a Magento store, so it does not require consent under GDPR and ePrivacy. It must still be disclosed in the cookie policy.
Some confirmation or error messages in the online store may not display correctly after an action, but browsing and checkout generally remain functional.
It is set directly by the Magento platform (Adobe Commerce), as a first-party cookie, on any online store built with this system, not by a third-party service.
The typical duration observed is 1 year, though this value can be adjusted in each Magento store's configuration.