What is the x-pp-s cookie?
x-pp-s is an HTTP cookie set by PayPal Inc. on the .paypal.com domain, not by the site the visitor is browsing. It is created when a page loads a PayPal payment button, checkout widget, login iframe, or any other PayPal-hosted component used for processing payments.
Because it is set directly by PayPal's infrastructure (even though triggered by the merchant's site), it belongs to the payment provider's technical cookies, needed for the payment session to work correctly.
What data it stores
PayPal does not publicly document the exact value format of this cookie. Based on publicly available information, x-pp-s stores a technical identifier tied to the current session with PayPal's services (e.g. internal routing, security state), and does not directly contain payment data such as card numbers.
Its value is sent only to PayPal's own servers (paypal.com) on requests to that domain, not to the merchant's site.
What it is used for
From PayPal's side, the cookie helps with:
- Maintaining session state while a visitor interacts with PayPal components (login, checkout, payment button)
- Fraud prevention and detection of suspicious behavior during payment
- Routing and load-balancing requests across PayPal's servers
For the merchant's site, its practical role is simply to let the PayPal payment flow work correctly and securely, with no direct involvement in the site's own marketing or analytics.
Does it require consent?
In CookieFix's classification, x-pp-s falls under strictly necessary: it is indispensable for completing a payment explicitly requested by the visitor, so it falls under the exemption in Romania's Law 506/2004 (transposing the ePrivacy Directive) and does not require prior consent to be set.
The site owner should still list it in the cookie policy, together with the provider (PayPal), purpose, and duration, as required by GDPR transparency obligations.
How to block or delete x-pp-s
A visitor can manually delete or block x-pp-s from browser settings (Chrome, Firefox, Edge, Safari — per-domain cookie management), though doing so may prevent completing a PayPal payment.
Being strictly necessary, this cookie should not be, and typically is not, auto-blocked by a consent tool before consent, to avoid breaking payment functionality. Platforms like CookieFix scan and classify a site's cookies automatically, blocking scripts from categories that genuinely require visitor consent (statistics, marketing) until it is given, while strictly necessary cookies like x-pp-s stay active so essential functions such as payment are not disrupted.
Frequently asked questions
It's a session cookie set by PayPal on the .paypal.com domain, used to support the security and correct operation of PayPal's payment and authentication processes.
Yes, it's classified as strictly necessary because it directly supports completing a payment the user has requested through PayPal, not marketing or analytics purposes.
Prior consent is not required, since it falls under the strictly necessary cookie exemption in Law 506/2004, but it should be listed in the site's cookie policy.
It's a session cookie, meaning it is automatically deleted when the browser is closed or the PayPal session ends.