What it does
TikTok’s current documentation lists `_ttp` as an advertising cookie used to measure and improve campaign performance and personalize the TikTok experience, including ads. It can appear as a first-party value on the website domain or a third-party value on `.tiktok.com`; TikTok currently documents a 13-month lifetime from last use. Current first-party companions include `ttcsid_*` and `ttclid`.
Older or implementation-specific scans may also find `_tt_enable_cookie`. The scanner recognises it, but TikTok’s current cookie table does not list that name, so do not present a historic flag as a universal current cookie unless it was actually observed.
On storefronts it usually arrives through a sales-channel app rather than a theme snippet, which means a clean theme can still produce this cookie.
What to write in a cookie declaration
List TikTok as the provider and the purpose as advertising measurement and optimization. Include companion names only when the current scan or vendor configuration supports them.
| Field | Value |
|---|---|
| Name | _ttp |
| Provider | TikTok |
| Purpose category | advertising |
| Consent category | Marketing |
| Expiry | 13 months from last use (current vendor documentation) (vendor default) |
| Storage | First- or third-party, depending on the cookie domain |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
Yes, in marketing. Under the named TikTok adapter the managed pixel is withheld until the category is granted, and the vendor revoke signal is sent on withdrawal.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
Why does _ttp appear when I removed the pixel from my theme?
Check every installation path: a platform or sales-channel app, a tag-manager container, another theme snippet and custom app code. On Shopify, the TikTok sales channel is one possible source, but the cookie alone does not identify which loader created it.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- TikTok for Business: using cookies with TikTok Pixel
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.