What it does
`_fbp` holds a browser identifier generated by the Meta Pixel. Events the pixel reports (page views, adds to cart, purchases) carry it, which is how Meta links activity on your site to its advertising and attribution systems.
It is written first-party because the pixel script runs in your page. The cookie is domain-scoped; it should not be described as one identical value following a browser across every site. Its significance comes from the pixel sending the identifier and event context to Meta, where correlation can also use account, click and other available signals.
What to write in a cookie declaration
Name Meta as the provider and describe the purpose as advertising measurement and audience building. A declaration that lists `_fbp` under your own domain with no provider named is technically true and practically misleading.
| Field | Value |
|---|---|
| Name | _fbp |
| Provider | Meta |
| Purpose category | advertising |
| Consent category | Marketing |
| Expiry | 90 days (vendor default) |
| Storage | First-party, written by script |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
Yes, and it belongs in marketing for this implementation. Under an opt-in model the managed pixel loader is not created before a grant. Under an opt-out model StrongPrivacy conservatively responds to Global Privacy Control by disabling every optional category before managed loaders run.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
Why is _fbp on my domain?
Because the pixel script runs in your page and writes the cookie through it. First-party storage has become the norm for advertising vendors as browsers restricted third-party cookies.
Does deleting _fbp stop Meta tracking?
It removes one identifier. It does not stop the pixel running, does not affect server-side Conversions API events, and the identifier is regenerated on the next load. Not loading the pixel is the control that works.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Meta for Developers: fbp and fbc parameters
Vendor documentation
Checked
- Meta: United States Regional Privacy Notice
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.