Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Marketing

sp_t Cookie (Spotify) – What It Is and How to Manage It

sp_t is an HTTP cookie set by Spotify on the .spotify.com domain, used to identify a browser over an extended period for advertising and tracking purposes. It is classified as a marketing cookie and, under ePrivacy and GDPR, requires the visitor's prior consent.

Name
sp_t
Provider
Spotify
Category
Marketing
Type
HTTP cookie
Lifetime
1 year
Domain / notes
.spotify.com
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the sp_t cookie?

sp_t is a cookie set by Spotify, the audio streaming platform, when a Spotify widget, embedded player, or share button appears on a third-party website, or when a user interacts directly with spotify.com. The associated domain is .spotify.com, meaning it is accessible across the service's subdomains.

On a non-Spotify site, this cookie typically appears as soon as an embedded player for a track, playlist, or podcast loads, even before the visitor actively interacts with it.

What data it stores

sp_t typically stores a unique identifier tied to the visitor's browser or device. The exact value format is not publicly documented by Spotify and may vary; no specific format should be assumed without confirmation from an official source.

The collected data is transmitted to Spotify's servers (part of Spotify AB, with operations also in the US) and used to link user activity to a long-term browser profile.

What it is used for

The stated purpose of this category of Spotify cookies is to support advertising and campaign performance measurement: recognizing returning visitors, correlating interactions with embedded Spotify content across different sites, and building audience-level usage statistics.

For the website operator hosting the embed, the cookie provides no direct functional benefit — it serves Spotify's advertising-related commercial interests rather than the operation of the embedded widget itself.

Does it require consent?

sp_t is classified by CookieFix as a marketing cookie (advertising/tracking). Under Romania's Law 506/2004 (transposing the ePrivacy Directive) and the GDPR, setting and reading this cookie requires the visitor's prior, freely given consent, obtained before the associated script runs.

  • The cookie must be explicitly listed in the site's cookie policy, with its purpose, provider, and duration.
  • It must not be set automatically on page load if the Spotify widget is embedded directly without prior blocking.
  • The website operator remains responsible for obtaining consent, even though the cookie is placed by a third party (Spotify).

How to block or delete sp_t

A visitor can manually delete or block sp_t from browser settings (Chrome, Firefox, Edge, Safari) under the per-site cookie management section, or use tracker-blocking extensions. Globally blocking third-party cookies also prevents this cookie from being set.

For site owners, a Spotify widget embedded directly on a page will load scripts that set sp_t before any consent is given. The fix is to automatically block these scripts until consent is obtained, using a CMP such as CookieFix, which intercepts player/embed content and only activates it after the visitor accepts the marketing category.

Frequently asked questions

It is not malicious, but it collects tracking data for advertising purposes, which is why it is classified as marketing and requires consent under GDPR.

The cookie is set by an embedded Spotify widget or player on the page (for example, a shared track or playlist), not by a direct Spotify account interaction.

The typical observed duration is around 1 year from when it is set, after which it expires automatically in the browser.

Not separately, but sp_t must be included under the marketing category in your banner, and the script that sets it must be blocked until the visitor explicitly accepts that category.

Updated 8 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.