What is the mid cookie?
„mid” is an HTTP cookie set on the .instagram.com domain, belonging to Meta Platforms (the company behind Instagram and Facebook). It typically appears when a visitor loads an embedded Instagram widget (such as a post or feed embed) or interacts with any page or plugin that connects to Instagram/Meta infrastructure, even without an account or being logged in.
Since it is set on the instagram.com domain, the cookie is not directly controlled by the site where it appears, but by Meta, as part of its embed integrations, share buttons, and tracking pixels.
What data it stores
The „mid” cookie stores a unique identifier tied to the visitor's browser, generated by Meta's systems to recognize the device on subsequent visits to Instagram or Facebook properties. Meta does not publish the exact value format, and the precise content may vary.
Data associated with this identifier is sent to Meta's servers and can be correlated with other tracking signals the company uses (such as the Facebook Pixel or other Meta cookies) to build cross-site and cross-device behavioral profiles.
What it is used for
Meta states that the primary purpose of „mid” is browser identification and authentication, supporting security and fraud-prevention measures. In practice, this type of persistent identifier also feeds into Meta's advertising ecosystem, helping recognize returning visitors for ad targeting and measurement.
For the administrator of a site displaying embedded Instagram content, the cookie brings no direct functional benefit — it primarily serves Meta's cross-site tracking interests.
Does it require consent?
„mid” is classified as a marketing/tracking cookie and is not strictly necessary for the host site to function. Under Romania's Law 506/2004 (transposing the ePrivacy Directive) and the GDPR, this type of cookie requires the visitor's prior, explicit, and informed consent before being set.
- Site owners must disclose this cookie in their cookie policy, including provider, purpose, and duration.
- Instagram embeds/widgets should not load automatically on page access — only after consent for the marketing category has been obtained.
- Romania's data protection authority (ANSPDCP) can sanction sites that set tracking cookies without valid consent.
How to block or delete mid
Visitors can manually delete or block this cookie via browser settings (Chrome, Firefox, Edge, Safari — cookie and site-data management sections), or use tracking-blocking extensions. Since the cookie belongs to the instagram.com domain, deleting it removes Meta's recognition on future visits.
For site owners, the correct approach is not manual deletion but preventing Instagram widgets from loading before consent is given. A CMP platform like CookieFix can automatically block Instagram/Facebook embed scripts until the visitor grants consent for the marketing category, preventing the „mid” cookie from being set without authorization.
Frequently asked questions
It is not malware, but it is a tracking identifier used by Meta for advertising and browser recognition, which raises privacy concerns if set without consent.
It usually appears because the page includes an Instagram/Meta widget, embed, or plugin that loads resources directly from the instagram.com domain.
Yes, since it is a marketing cookie set by Meta, it requires the visitor's prior consent under the GDPR and Romania's Law 506/2004.
The typical duration observed is about 1 year from being set, after which it expires automatically unless renewed by a new visit.