Tracker library

Stripe: what it is, what it sets, and how to gate it.

Payments and fraud prevention. On an active checkout, Stripe may support a service the visitor requested; sitewide loading and Stripe’s separate controller activities need a distinct, documented analysis.

Vendor
Stripe
Scanner category
functional
Consent category
Necessary, on checkout paths
Control
Custom script or container tag

What it is

Stripe documents identifiers used for fraud detection and payment security. On an active checkout they may be strictly necessary for a payment service the visitor requested, but necessity is a narrow, purpose-specific legal test rather than a property of the vendor name.

Stripe’s own guidance is to load Stripe.js on every page for fraud detection to work best. That is a real security argument, and it is in tension with data minimisation: a visitor reading a blog post is not transacting.

What a scan matches

A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Stripe is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.

  • stripe.com
  • js.stripe.com
  • stripe.network

Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.

CookieWhat it is for
__stripe_midMachine identifier used for fraud detection
__stripe_sidSession identifier for the current checkout

Controlling it with consent

Document why Stripe is loaded on each path, which Stripe role applies to the processing, and which exemption or lawful basis you rely on. Loading it only when a payment flow begins is the narrower design; sitewide fraud collection needs its own proportionality and transparency analysis.

Either way, say what you are doing in the cookie declaration rather than leaving Stripe unexplained in a list.

No named adapter: choose the appropriate control

The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.

What breaks if it is refused: payment processing and fraud detection if it is blocked during an active checkout. Decide the loading point with payment, security and privacy owners rather than applying one sitewide category by default.

Verifying it

Check which paths actually load js.stripe.com. Finding it on a marketing landing page is normal and worth a deliberate decision rather than an accident.

  • Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
  • After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
  • After granting the relevant category: the expected loader or embed appears and the feature behaves normally
  • After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior

Common questions

Do Stripe cookies need consent?

Potentially not on an active payment path where the exact storage is strictly necessary to provide the requested payment securely. That conclusion depends on purpose, configuration and jurisdiction. Sitewide loading for broader fraud signals requires a separate documented analysis and should not inherit the checkout conclusion automatically.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.