What the gist_oauth_csrf cookie does
This cookie is set by Gist to ensure the user that started the oauth flow is the same user that completes it.
Who sets it
Consent category: strictly necessary
Strictly necessary cookies keep a site working: sessions, security, load balancing and remembering the visitor's consent choice. They are exempt from consent under the ePrivacy rules, but a cookie policy still has to list them.
| Name | gist_oauth_csrf |
|---|---|
| Category | Strictly necessary |
| Lifetime | Deleted when oauth state is validated |
| Set by | GitHub |
Other cookies from the same vendor
app_manifest_tokencolor_mode_device_iddotcom_userenterprise_trial_redirect_tofileTreeExpanded_gh_ent_gh_sess
Is this cookie on your site?
A free scan lists every cookie your site sets, classifies each one the way this page does, and shows which are set before the visitor has consented. Scan your site with Conzent, or look up another cookie.
From the Conzent cookie database, last updated 2026-09-27. Descriptions come from vendor documentation, cookie policies and our own scans; write to support@getconzent.com to correct one.