What is the storefront_digest cookie?
storefront_digest is an HTTP cookie set by Shopify on online stores running on this platform. It appears automatically as soon as a visitor accesses a Shopify-powered site, generated by the commerce engine (checkout, cart, storefront theme) rather than by an optional module a merchant can turn on or off.
It is not set directly by the store owner but by the underlying Shopify infrastructure. In practice, any store built on Shopify will have this cookie present, regardless of the theme or installed apps.
What data it stores
The cookie stores a technical identifier (a "digest", i.e. a checksum/hash-type value) used internally by Shopify to verify the integrity and validity of the visitor's store session. The exact value format varies and is not publicly documented in detail by Shopify.
Data is sent to Shopify's servers (the store's domain and associated Shopify infrastructure), not to external third parties. The typical lifespan is 2 years from setting or renewal.
What it is used for
The cookie's purpose is strictly functional: it helps the Shopify platform maintain the consistency and security of the visitor's shopping session across different store pages (product, cart, checkout). It is part of the mechanisms that make basic online store operation possible – adding products to the cart, going through checkout, and preventing session errors or tampering.
For the store owner, this cookie requires no configuration; it comes built into the Shopify platform by default.
Does it require consent?
CookieFix classifies storefront_digest as strictly necessary, since it is essential for the store's basic operation (cart, checkout, preventing session errors).
- Under the ePrivacy Directive (2002/58/EC) and its national transposition, cookies strictly necessary to provide a service explicitly requested by the user (e.g. the shopping cart) do not require prior consent.
- The store owner must still disclose it in the cookie policy, including its purpose and duration, for GDPR transparency (Art. 13).
- It should not be placed among categories that only activate after the consent banner is accepted.
How to block or delete storefront_digest
A visitor can delete or block this cookie from browser settings (Chrome, Firefox, Safari, Edge – per-site cookie management), though blocking it may break the shopping cart and checkout process on the Shopify store in question.
From the store owner's perspective, since it is strictly necessary, storefront_digest does not need to be, and generally cannot be, blocked pending consent by a CMP like CookieFix, unlike analytics or marketing cookies – it runs implicitly as part of Shopify's infrastructure. CookieFix instead focuses on automatically blocking scripts from categories that actually require consent (analytics, marketing), leaving strictly necessary cookies like this one unaffected.
Frequently asked questions
It's an HTTP cookie set by Shopify on online stores built with the platform, used for technical validation of the visitor's shopping session.
No, it is classified as strictly necessary, so it does not require prior consent under the ePrivacy Directive, but it must be disclosed in the site's cookie policy.
The typical duration is 2 years from setting or last renewal, based on Shopify's practices.
You may experience issues using the shopping cart or completing checkout on that Shopify store, since the cookie is part of the core session mechanisms.