Cookie library

The YSC cookie

A session-scoped YouTube security cookie that Google says helps ensure requests in a browsing session are made by the user rather than another site.

Set by
YouTube
Classified as
media
Typical expiry
Session
Storage
Third-party

What it does

Google currently describes `YSC` as a security cookie that helps ensure requests during a browsing session are made by the user and not by another site. It lasts for the browsing session. Record the observed host and player context as well, because a cookie name alone does not establish which embed action caused it.

What to write in a cookie declaration

List it with the rest of the YouTube set, with "session" as the expiry.

FieldValue
NameYSC
ProviderYouTube
Purpose categorymedia
Consent categoryMedia
ExpirySession (vendor default)
StorageThird-party

Treat the expiry as indicative

The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.

Common questions

Is a session cookie exempt?

Only where it is strictly necessary for a service the visitor requested. A video embed the visitor has not yet clicked is not that.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.