Definition
A first-party cookie is a small piece of data stored by the website the user is actually visiting, under that site's own domain, and readable only by that site. It is the mechanism behind essential functions - keeping a user logged in, holding a session, remembering language and preferences - and behind first-party analytics that measure how people use that one site.
It contrasts with a third-party cookie, set by a domain other than the one in the address bar (typically an ad or tracking network embedded in the page), which can follow a user across many sites.
Browsers treat the two very differently. First-party cookies are broadly still supported because sites need them to function; third-party cookies are blocked by default in most browsers.
But first-party cookies are not unrestricted: tracking-prevention features cap the lifetime of script-set first-party cookies in some browsers, and consent law still requires permission for any first-party cookie that is not strictly necessary, such as analytics or marketing.
In context
For iGaming, the first-party versus third-party distinction shapes what still works in measurement and marketing. An operator's own login, session and preference cookies are first-party and unaffected.
First-party analytics on the operator's or affiliate's own site continues to work, subject to consent for the non-essential ones. What has broken is cross-site third-party tracking: retargeting pools, cross-domain attribution, and any affiliate tracking that relied on a third-party cookie being readable on the operator's site.
This is why the industry moved to click-ID server-to-server postbacks and first-party or server-side click capture.
The consent point is often misunderstood. "First-party" does not mean "no consent needed".
A first-party analytics or advertising cookie is still non-essential and still requires opt-in under EU-style rules, and firing it on page load before the banner is answered is a breach whether it is first-party or third-party. Affiliates should set only strictly necessary first-party cookies before consent, gate the rest behind the banner, and design tracking so that the essential attribution (click ID passed through to a server-side postback) does not depend on a cookie that a browser might cap or a user might decline.
Framing first-party data as the durable foundation is correct, but it has to be consented, documented, and used only for the purposes the user agreed to.
Worked example
An affiliate audits its cookies: session and preference cookies are first-party and strictly necessary, so they load immediately; the first-party analytics and advertising cookies now wait for consent. Attribution to operators runs on a click ID carried into a server-side postback, so it survives third-party-cookie blocking and browser lifetime caps on first-party cookies.
Related terms
Frequently asked questions
Browse more iGaming terms in our glossary.
← Back to glossary