Cookie library

The __stripe_mid cookie

A Stripe identifier used for fraud prevention. It may be necessary during a requested payment flow; that conclusion should not automatically be extended to every page.

Set by
Stripe
Classified as
functional
Typical expiry
1 year
Storage
First-party, written by script

What it does

Stripe documents `__stripe_mid` and related storage as supporting fraud prevention and payment security. During an active checkout this may be strictly necessary for a payment the visitor requested, subject to the exact implementation and applicable rule.

Stripe recommends loading Stripe.js on every page so fraud signals are richer. That is a real security argument and it sits in tension with data minimisation, because a visitor reading a blog post is not transacting.

What to write in a cookie declaration

Describe its fraud-prevention purpose, the paths where Stripe.js loads, and the role Stripe has in the relevant processing. If you classify it as necessary, retain the purpose-specific assessment supporting that conclusion.

FieldValue
Name__stripe_mid
ProviderStripe
Purpose categoryfunctional
Consent categoryNecessary on payment paths
Expiry1 year (vendor default)
StorageFirst-party, written by script

Treat the expiry as indicative

The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.

Common questions

Should I load Stripe.js on every page?

Stripe recommends broad loading for richer fraud signals, while payment-path loading collects less from non-transacting visitors. There is no universal answer: document the security benefit, data flow, Stripe’s role, jurisdiction and less intrusive alternatives, and obtain legal advice for the chosen scope.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.