What is the X-Magento-Vary cookie?
X-Magento-Vary is a technical cookie generated automatically by the Magento platform (open source and Adobe Commerce), used on online stores built on this technology. It is not a third-party cookie but part of Magento's core application logic.
The cookie appears as soon as a visitor loads any page of a Magento store, whether or not they interact with forms, the shopping cart, or simply browse the catalog.
What data it stores
The cookie stores a server-generated hash value used by Magento's caching mechanism (Full Page Cache / Varnish) to distinguish between cached page variants depending on the session context (e.g. personalized content, cart contents, active discounts). The exact value format varies between stores and typically does not contain directly identifying personal data.
The data is stored in the visitor's browser and sent only to the store's own server (the domain running Magento), not to third parties.
What it is used for
The cookie's purpose is purely technical: it helps the Magento server determine which cached page version should be served to a given visitor, so that users with different session states (full cart, active promotions, customer segment, etc.) see the correct content rather than a generic cached version.
For the site owner, this cookie directly supports the store's basic operation: without it, the caching system may serve incorrect or inconsistent pages to different visitors.
Does it require consent?
Under CookieFix's classification, X-Magento-Vary is categorized as strictly necessary (required for the site to function). Under Article 5(3) of the ePrivacy Directive, transposed in Romania through Law 506/2004, strictly necessary cookies do not require prior visitor consent.
- No visitor opt-in is required before it is set.
- It should still be listed, with its purpose and duration, in the site's cookie policy.
- The site owner should be able to justify, if requested by a data protection authority, why this cookie is essential for functionality.
How to block or delete X-Magento-Vary
A visitor can delete or block this cookie from browser settings (Chrome, Firefox, Edge, Safari), under the site data/cookie management section. Blocking it may affect the accuracy of cached page rendering on the Magento store.
For site owners, since it is strictly necessary, this cookie should not be blocked by the consent banner — a CMP like CookieFix automatically classifies it as "necessary" and excludes it from the blocking applied to statistics or marketing scripts, which only run after consent is given.
Frequently asked questions
No, since it is strictly necessary for Magento's caching to work correctly, it does not require prior consent under Law 506/2004, but it must be listed in the cookie policy.
It is set automatically by the Magento platform (open source or Adobe Commerce) on any online store built on it, not by a third-party vendor.
The browser will receive a new value on the next page load; deleting it doesn't block navigation, but may temporarily affect correct display of cached pages.
It is a session cookie, so it is automatically deleted when the visitor closes their browser.