What it does
Stripe documents `__stripe_mid` and related storage as supporting fraud prevention and payment security. During an active checkout this may be strictly necessary for a payment the visitor requested, subject to the exact implementation and applicable rule.
Stripe recommends loading Stripe.js on every page so fraud signals are richer. That is a real security argument and it sits in tension with data minimisation, because a visitor reading a blog post is not transacting.
What to write in a cookie declaration
Describe its fraud-prevention purpose, the paths where Stripe.js loads, and the role Stripe has in the relevant processing. If you classify it as necessary, retain the purpose-specific assessment supporting that conclusion.
| Field | Value |
|---|---|
| Name | __stripe_mid |
| Provider | Stripe |
| Purpose category | functional |
| Consent category | Necessary on payment paths |
| Expiry | 1 year (vendor default) |
| Storage | First-party, written by script |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
Blocking it during an active checkout may break payment or fraud controls. Sitewide loading is a separate, broader collection decision and needs its own necessity, proportionality and transparency analysis.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
Should I load Stripe.js on every page?
Stripe recommends broad loading for richer fraud signals, while payment-path loading collects less from non-transacting visitors. There is no universal answer: document the security benefit, data flow, Stripe’s role, jurisdiction and less intrusive alternatives, and obtain legal advice for the chosen scope.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Stripe Privacy Center
Vendor documentation
Checked
- Stripe Data Processing Agreement
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.