What it is
Mixpanel tracks in-product behaviour against a distinct ID, which is usually set to your own user identifier once someone signs in. That is a stronger identification than a page-analytics cookie, and it is deliberate: the value of product analytics comes from following a known user.
It also changes where the consent conversation happens. A signed-in product has a relationship, a privacy notice and often a contract, which is a different setting from a marketing page a stranger has just landed on.
What a scan matches
A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Mixpanel is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.
- mixpanel.com
- mxpnl.com
Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.
| Cookie | What it is for |
|---|---|
| mp_* | Mixpanel distinct ID and super properties, matched by prefix |
| mixpanel* | Related Mixpanel state |
Controlling it with consent
No named adapter. Gate it as a custom script attached to analytics on public pages.
Inside an authenticated product, consider whether your legal basis and disclosures actually work differently there. That is a decision to make and write down rather than to leave implicit, and if consent is the basis, the in-product preference has to be honoured by the same runtime.
No named adapter: choose the appropriate control
The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.
What breaks if it is refused: product analytics for refusing visitors, which for a marketing site is usually acceptable and for a product is a decision with real cost.
Verifying it
Before consent on a public page there should be no request to mixpanel.com or mxpnl.com and no mp_ cookie. Inside the product, check that a user who has opted out in their settings is not still being tracked.
- Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
- After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
- After granting the relevant category: the expected loader or embed appears and the feature behaves normally
- After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior
Common questions
Does product analytics inside a logged-in app need a cookie banner?
The storage rule does not stop at the login wall. What changes is that you have other disclosure routes and possibly another basis. Decide deliberately and document it; do not assume authentication removes the question.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Mixpanel: JavaScript SDK documentation
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.