What a first-party cookie is

A cookie is a small text record a server places in the visitor’s browser. A first-party cookie is one whose domain matches the domain of the current site. If the visitor has opened shop.example.com, then cookies on shop.example.com or .shop.example.com are first-party.

Browsers handle them in full: no automatic lifetime cap when they are set through the Set-Cookie header, no automatic blocking. That makes them the basis for:

  • Sign-in and session management
  • Holding the basket for visitors who have not registered
  • Identifying anonymous visitors inside personalization platforms
  • Language and regional settings

First-party against third-party

Property First-party cookie Third-party cookie
Setting domain The current site’s domain An outside domain
Browser blocking None Safari (ITP), Firefox (ETP), Chrome (2024+)
Main use Sign-in, basket, personalization Cross-site retargeting, analytics
GDPR position Necessary cookies need no consent Explicit consent required

ITP and the Safari limits

Since 2017 Apple’s Safari has tightened its handling of cookies through intelligent tracking prevention. The key restriction: first-party cookies set through JavaScript (document.cookie) live for a maximum of seven days.

That matters for personalization platforms that rely on long-term identification of anonymous visitors. The answer is to set the identifying cookie on the server, through the Set-Cookie HTTP header, rather than from a JavaScript snippet. Server-set first-party cookies are not capped by ITP.

The first-party approach for personalization platforms

Personalization platforms historically operated third-party: the script loaded from the vendor’s own CDN and the cookie was set on the vendor’s domain. As browsers tightened up, that arrangement stopped being reliable.

The modern approach is CNAME delegation or a reverse proxy:

The traditional arrangement:
Script: analytics.vendor.com/script.js
Cookie: _vid=123 (domain: vendor.com) → THIRD-PARTY

The first-party arrangement:
Script: recs.shop.example.com/script.js  ← CNAME → vendor edge
Cookie: _vid=123 (domain: .shop.example.com) → FIRST-PARTY

Important: moving to a first-party arrangement needs DNS changes on the client’s side and support from the vendor. Without it, once Chrome has fully dropped third-party cookies, part of the analytics and personalization will behave incorrectly for the iOS audience.