Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Marketing

SAPISID Cookie (Google) – What It Is and Its Purpose

SAPISID is a cookie set by Google on the .google.com domain, used for account authentication and to link a signed-in user's identity across Google services, including ad personalization. It is classified as a marketing cookie because it contributes to cross-site tracking and ad targeting.

Name
SAPISID
Provider
Google
Category
Marketing
Type
HTTP cookie
Lifetime
2 years
Domain / notes
.google.com
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the SAPISID cookie?

SAPISID (part of Google's authentication cookie family, alongside SID, HSID, SSID and __Secure-3PAPISID, as documented publicly by Google) is set by Google domains when a user is signed into a Google account.

On a third-party website, SAPISID usually appears indirectly, through Google integrations such as Google Ads, reCAPTCHA, Google Maps, Google sign-in buttons, or other embeds that load resources from google.com and can read or set Google session cookies in that context.

What data it stores

The cookie stores a secure identifier tied to the user's Google account session. Its value is an opaque, cryptographically generated string, with no information directly readable by the website operator.

Data is transmitted to Google's servers (.google.com and related services, e.g. Google Ads, YouTube, or account-linked Google Analytics). The embedding website has no access to the cookie's contents; it only triggers the request that sets it.

What it is used for

For Google, SAPISID helps verify the identity of a signed-in user and protects API requests against cross-site request forgery, using a derived token combined with the request's origin.

In practice, this mechanism is also used to tie user activity to a Google account for ad personalization and cross-site measurement, which is why CookieFix classifies it as a marketing cookie rather than strictly necessary when it appears on a third-party site.

Does it require consent?

CookieFix classifies SAPISID under the marketing category. Under GDPR and the ePrivacy Directive (implemented in Romania via Law 506/2004), marketing/tracking cookies require the visitor's prior, explicit consent through a valid consent banner.

  • Site owners must disclose this cookie in their cookie policy, listing provider, purpose, and duration.
  • The script that sets it (e.g. Google Ads, a Google sign-in widget) must be blocked until consent for the marketing category is obtained.
  • Declining consent must not break the site's core functionality.

How to block or delete SAPISID

Visitors can delete or block this cookie through browser settings (Chrome, Firefox, Edge, Safari all offer per-site cookie management), or sign out of their Google account to limit the link to their identity. Privacy-focused browser extensions can also prevent it from being set.

For site owners, blocking needs to happen automatically, before consent is given. A CMP like CookieFix can intercept and block Google scripts that set SAPISID (e.g. Google Ads, sign-in integrations) until the visitor accepts the marketing category, preventing the cookie from being set without a legal basis.

Frequently asked questions

It's not malicious, but it is a tracking cookie Google uses for identification and advertising, which is why it requires consent on third-party websites.

It typically lasts around 2 years, though Google may renew or invalidate it earlier, such as when the user signs out or changes account security settings.

On third-party sites embedding Google services, CookieFix classifies it as a marketing cookie, since it contributes to ad personalization and cross-site tracking rather than pure technical functionality.

Yes, if your site loads Google services that set this cookie, you must obtain prior consent under GDPR and block the relevant script until the visitor accepts.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.