What a first-party cookie is
A cookie is a small text record a server places in the visitor’s browser. A first-party cookie is one whose domain matches the domain of the current site. If the visitor has opened shop.example.com, then cookies on shop.example.com or .shop.example.com are first-party.
Browsers handle them in full: no automatic lifetime cap when they are set through the Set-Cookie header, no automatic blocking. That makes them the basis for:
- Sign-in and session management
- Holding the basket for visitors who have not registered
- Identifying anonymous visitors inside personalization platforms
- Language and regional settings
First-party against third-party
| Property | First-party cookie | Third-party cookie |
|---|---|---|
| Setting domain | The current site’s domain | An outside domain |
| Browser blocking | None | Safari (ITP), Firefox (ETP), Chrome (2024+) |
| Main use | Sign-in, basket, personalization | Cross-site retargeting, analytics |
| GDPR position | Necessary cookies need no consent | Explicit consent required |
ITP and the Safari limits
Since 2017 Apple’s Safari has tightened its handling of cookies through intelligent tracking prevention. The key restriction: first-party cookies set through JavaScript (document.cookie) live for a maximum of seven days.
That matters for personalization platforms that rely on long-term identification of anonymous visitors. The answer is to set the identifying cookie on the server, through the Set-Cookie HTTP header, rather than from a JavaScript snippet. Server-set first-party cookies are not capped by ITP.
The first-party approach for personalization platforms
Personalization platforms historically operated third-party: the script loaded from the vendor’s own CDN and the cookie was set on the vendor’s domain. As browsers tightened up, that arrangement stopped being reliable.
The modern approach is CNAME delegation or a reverse proxy:
The traditional arrangement:
Script: analytics.vendor.com/script.js
Cookie: _vid=123 (domain: vendor.com) → THIRD-PARTY
The first-party arrangement:
Script: recs.shop.example.com/script.js ← CNAME → vendor edge
Cookie: _vid=123 (domain: .shop.example.com) → FIRST-PARTY
Important: moving to a first-party arrangement needs DNS changes on the client’s side and support from the vendor. Without it, once Chrome has fully dropped third-party cookies, part of the analytics and personalization will behave incorrectly for the iOS audience.