Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Marketing

„mid” Cookie (Instagram/Meta) – What It Is and Its Role

The „mid” cookie is set by Instagram (Meta) to identify a visitor's browser over the long term, primarily for advertising and security purposes. It is classified as a marketing/tracking cookie and, in most cases, requires prior user consent under EU and Romanian data protection law.

Name
mid
Provider
Instagram (Meta)
Category
Marketing
Type
HTTP cookie
Lifetime
1 year
Domain / notes
.instagram.com
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the mid cookie?

„mid” is an HTTP cookie set on the .instagram.com domain, belonging to Meta Platforms (the company behind Instagram and Facebook). It typically appears when a visitor loads an embedded Instagram widget (such as a post or feed embed) or interacts with any page or plugin that connects to Instagram/Meta infrastructure, even without an account or being logged in.

Since it is set on the instagram.com domain, the cookie is not directly controlled by the site where it appears, but by Meta, as part of its embed integrations, share buttons, and tracking pixels.

What data it stores

The „mid” cookie stores a unique identifier tied to the visitor's browser, generated by Meta's systems to recognize the device on subsequent visits to Instagram or Facebook properties. Meta does not publish the exact value format, and the precise content may vary.

Data associated with this identifier is sent to Meta's servers and can be correlated with other tracking signals the company uses (such as the Facebook Pixel or other Meta cookies) to build cross-site and cross-device behavioral profiles.

What it is used for

Meta states that the primary purpose of „mid” is browser identification and authentication, supporting security and fraud-prevention measures. In practice, this type of persistent identifier also feeds into Meta's advertising ecosystem, helping recognize returning visitors for ad targeting and measurement.

For the administrator of a site displaying embedded Instagram content, the cookie brings no direct functional benefit — it primarily serves Meta's cross-site tracking interests.

Does it require consent?

„mid” is classified as a marketing/tracking cookie and is not strictly necessary for the host site to function. Under Romania's Law 506/2004 (transposing the ePrivacy Directive) and the GDPR, this type of cookie requires the visitor's prior, explicit, and informed consent before being set.

  • Site owners must disclose this cookie in their cookie policy, including provider, purpose, and duration.
  • Instagram embeds/widgets should not load automatically on page access — only after consent for the marketing category has been obtained.
  • Romania's data protection authority (ANSPDCP) can sanction sites that set tracking cookies without valid consent.

How to block or delete mid

Visitors can manually delete or block this cookie via browser settings (Chrome, Firefox, Edge, Safari — cookie and site-data management sections), or use tracking-blocking extensions. Since the cookie belongs to the instagram.com domain, deleting it removes Meta's recognition on future visits.

For site owners, the correct approach is not manual deletion but preventing Instagram widgets from loading before consent is given. A CMP platform like CookieFix can automatically block Instagram/Facebook embed scripts until the visitor grants consent for the marketing category, preventing the „mid” cookie from being set without authorization.

Frequently asked questions

It is not malware, but it is a tracking identifier used by Meta for advertising and browser recognition, which raises privacy concerns if set without consent.

It usually appears because the page includes an Instagram/Meta widget, embed, or plugin that loads resources directly from the instagram.com domain.

Yes, since it is a marketing cookie set by Meta, it requires the visitor's prior consent under the GDPR and Romania's Law 506/2004.

The typical duration observed is about 1 year from being set, after which it expires automatically unless renewed by a new visit.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.