What is the MATOMO_SESSID cookie?
MATOMO_SESSID is an HTTP cookie set by Matomo, an open-source web analytics platform that can be self-hosted or used via Matomo Cloud. It typically appears when someone logs into the Matomo administration dashboard (the reporting interface), not simply because a visitor lands on the monitored website.
On some setups this cookie may also be seen on the domain hosting the Matomo instance, if the site administrator accesses the control panel from the same browser used for regular browsing.
What data it stores
MATOMO_SESSID stores a randomly generated session identifier that the server uses to recognize an active login session within the Matomo application. The exact value format and length depend on the server configuration and the installed Matomo version, so they can vary.
The data is sent to the Matomo server (self-hosted or the provider's cloud instance) to validate the logged-in user's session. It is not intended to collect behavioral data about visitors on the public-facing website.
What it is used for
The cookie's purpose is purely functional: it keeps a user (usually an administrator or analyst) logged into the Matomo interface so they aren't signed out on every dashboard page they view.
For a site using Matomo as its analytics tool, this cookie doesn't measure traffic or support marketing — it supports the correct functioning of administrative access to the analytics platform itself.
Does it require consent?
CookieFix classifies MATOMO_SESSID as strictly necessary, since it supports an essential technical function (authentication) rather than visitor tracking or marketing.
- Under Article 4(5) of Law 506/2004 (Romania's transposition of the ePrivacy Directive) and ANSPDCP guidance, cookies strictly necessary for a service explicitly requested by the user are exempt from prior consent requirements.
- Website operators should still list this cookie in their cookie policy, with its purpose and duration, for GDPR transparency.
- If this cookie appears on the public side of a site (not just the admin area), it's worth checking whether the Matomo installation also collects additional data that would require consent.
How to block or delete MATOMO_SESSID
A visitor can delete or block this cookie via browser settings (Chrome, Firefox, Edge, Safari – cookie and site data management), either globally or specifically for the domain running Matomo. Blocking it will automatically log out the authenticated user from the Matomo interface on the next action.
For site administrators, since this cookie is strictly necessary, it should not be blocked by a CMP before consent — it's legally exempt. A consent platform like CookieFix can still automatically block Matomo's front-end tracking scripts (if they set additional analytics cookies) until consent is obtained, without affecting the internal Matomo dashboard's functionality.
Frequently asked questions
No, it normally manages the login session of users inside the Matomo interface, not the behavior of the site's public visitors.
No, as a strictly necessary cookie supporting a technical function (login), it's exempt from prior consent under Romania's Law 506/2004, but it should still be listed in the cookie policy.
It's a session cookie, so it's automatically deleted when the browser closes or the login session expires.
The user logged into the Matomo interface will be signed out and need to log in again; it has no effect on the public-facing website.