What is the sb cookie?
"sb" is an HTTP cookie set by Facebook, usually when a visitor interacts with a Facebook element (Like/Share button, comments plugin, Facebook Pixel, or any request to a facebook.com domain) embedded on a third-party site, or when visiting facebook.com directly.
Its name is believed to stand for "secure browser" and it is used by Meta as part of its browser identification infrastructure, separate from account login sessions. It commonly appears alongside other Facebook cookies such as datr or fr.
What data it stores
The cookie stores a unique identifier tied to the browser, generated by Facebook on first interaction. Its value is an opaque alphanumeric string generated and controlled entirely by Meta; the exact format is not publicly documented and may vary.
The data is sent to Facebook/Meta servers whenever the browser makes a request to a facebook.com domain, including from third-party sites that load Facebook resources.
What it is used for
For Facebook, the "sb" cookie helps identify the browser for account security purposes (such as detecting suspicious activity or unauthorized access) and contributes to linking browsing activity with the company's advertising profiles.
For the website operator embedding Facebook components, this cookie serves no direct user-facing function on the site itself — it's a side effect of including Meta tools (pixel, social widgets) — but it remains the operator's responsibility to disclose it.
Does it require consent?
- CookieFix category: marketing (advertising/tracking)
- Consent required: yes – it is not strictly necessary for the site's operation, so prior consent is required under the ePrivacy Directive (2002/58/EC) and applicable GDPR legal basis for advertising/tracking processing.
- What the site operator must do: disclose the "sb" cookie and Facebook as a provider in the cookie policy, classify it under the marketing category in the consent banner, and ensure the Facebook script (pixel, social widget) does not run before the visitor gives explicit consent.
How to block or delete sb
A visitor can delete the "sb" cookie via browser settings (Chrome, Firefox, Safari, Edge – cookie management for facebook.com), use private/incognito mode, or install tracker-blocking extensions. Deleting it does not affect the functioning of the third-party site where it appears.
For site operators aiming for compliance, the practical approach is to automatically block Facebook scripts (pixel, social buttons) until consent is given. A CMP platform like CookieFix can do this automatically, preventing Meta scripts from loading until the visitor accepts the marketing category.
Frequently asked questions
It's a cookie used by Facebook to identify the visitor's browser, with a stated security role but also a function in tracking behavior for advertising purposes.
It typically lasts 2 years from the time it's set or last updated, based on Facebook's practices.
Yes, since it's classified as a marketing/tracking cookie, it requires prior consent under GDPR and the ePrivacy Directive.
By configuring a CMP that blocks Facebook scripts (pixel, social widgets) until the visitor accepts the marketing category.