What the hubspotapi-csrf cookie does
This is used for CSRF prevention - preventing third party websites from accessing your data. Expires after a year.
Who sets it
Consent category: strictly necessary
Strictly necessary cookies keep a site working: sessions, security, load balancing and remembering the visitor's consent choice. They are exempt from consent under the ePrivacy rules, but a cookie policy still has to list them.
| Name | hubspotapi-csrf |
|---|---|
| Category | Strictly necessary |
| Lifetime | 1 year |
| Set by | HubSpot |
Other cookies from the same vendor
hs-membership-csrfhs-messages-hide-welcome-messagehs-messages-is-openhs_ab_test__hs_cookie_cat_pref__hs_do_not_track__hs_gpc_banner_dismiss__hs_initial_opt_in
Is this cookie on your site?
A free scan lists every cookie your site sets, classifies each one the way this page does, and shows which are set before the visitor has consented. Scan your site with Conzent, or look up another cookie.
From the Conzent cookie database, last updated 2026-09-27. Descriptions come from vendor documentation, cookie policies and our own scans; write to support@getconzent.com to correct one.