What is the msToken cookie?
msToken is an HTTP cookie set by the .tiktok.com domain, used by TikTok on sites and pages that embed TikTok content (video widgets, share buttons, the TikTok advertising pixel) or when a user interacts directly with the TikTok platform.
The cookie usually appears the first time a TikTok script or widget loads on a page, regardless of whether the visitor has a TikTok account. It is part of the technical infrastructure TikTok uses to authenticate and sign requests sent to its servers.
What data it stores
msToken stores a token generated by TikTok's systems, used to validate and sign requests sent to the platform's internal API. The value is an encrypted alphanumeric string with no structure publicly documented by TikTok.
Data associated with this cookie is sent to TikTok (ByteDance) servers, which, according to the company's privacy policies, may include infrastructure located outside the European Economic Area. Exact transfer destinations can vary depending on the user's region and TikTok's current policy.
What it is used for
From TikTok's perspective, msToken is used to protect its APIs against automated or abusive access (bots, scraping) and to maintain session continuity when a user interacts with TikTok content.
For a site owner embedding TikTok widgets or the TikTok pixel, this cookie indirectly supports correct integration behavior (video display, conversion tracking for TikTok Ads campaigns), but offers no direct control over the data TikTok collects.
Does it require consent?
CookieFix classifies msToken as a marketing/tracking cookie, since it is tied to TikTok's advertising and analytics infrastructure. Under GDPR and the ePrivacy Directive (transposed in Romania via Law 506/2004), this type of cookie cannot be set before the visitor gives explicit consent.
- The site owner must list the cookie in the cookie policy, including provider, purpose, and duration.
- The script that generates msToken (TikTok widget, TikTok pixel) must load only after consent, not by default on page load.
- Visitors must be able to refuse or withdraw consent as easily as they granted it.
How to block or delete msToken
A visitor can delete or block msToken through browser cookie settings (per-domain management) or by using tracking-blocking extensions. Blocking it generally doesn't affect the host site's core functions, but may prevent embedded TikTok widgets from displaying correctly.
For site owners, the safest approach is to automatically block TikTok scripts until consent is given, using a consent management platform. CookieFix, for example, can intercept and block the script that sets msToken until the visitor makes a choice in the banner.
Frequently asked questions
It's a technical cookie used by TikTok to validate and sign requests sent to its API, typically appearing when TikTok widgets or the TikTok pixel load on a site.
Its typical duration is around 10 days, after which the cookie expires and, if needed, is regenerated.
Yes, since it's classified as a marketing/tracking cookie, it requires prior consent under GDPR and ePrivacy before being set.
It's not technically harmful, but it supports TikTok's tracking infrastructure, so it must be disclosed and managed through consent like any marketing cookie.