| Cookie | Category | Purpose |
|---|---|---|
a0_users:sess | Strictly necessary | Used for CSRF protection in Classic Universal Login flows. |
a0_users:sess.sig | Strictly necessary | Used for CSRF protection in Classic Universal Login flows. |
auth0 | Functional | Used to implement the Auth0 session layer. |
auth0-mf | Functional | Used to establish the trust level for a given device. |
auth0-mf_compat | Functional | Fallback cookie for multi-factor authentication on browsers that don't support the sameSite=None attribute. |
auth0_compat | Functional | Fallback cookie for single sign-on on browsers that don't support the sameSite=None attribute. |
did | Functional | Device identification for attack protection. |
did_compat | Functional | Fallback cookie for anomaly detection on browsers that don't support the sameSite=None attribute. |
__txn_ | Functional | The __txn_ cookie is an Auth0 transaction cookie used during the login process to securely manage the authentication flow between your application and Auth0 |
Running Auth0 on your site? A free Conzent scan shows which of these cookies are set before consent, and the banner blocks them until the visitor agrees.
Last updated 2026-09-27.