To track visitors, Matomo (Piwik) by default uses 1st party cookies, set on the domain of your website. Cookies created by Matomo start with: _pk_ref, _pk_cvar, _pk_id, _pk_ses. When you use the Heatmap & Session Recording plugin, a cookie _pk_hsr will be created.

When you exclude yourself from being tracked using the cookie method or using the iframe opt-out method, Matomo will create a cookie matomo_ignore set on the domain of your Matomo server. When Matomo is setup on a different domain than the website being tracked, the cookie will a third party cookie. Please note that the matomo_ignore or matomo_ignore cookie does not contain personal information or any ID and the cookie value is the same for all visitors. Also when the opt-out feature is used, there is a cookie called MATOMO_SESSID being created, this cookie is only temporary (it is called a nonce and helps prevent CSRF security issues).

You can also Disable all first party cookies from being set — for example for privacy reasons.

Matomo by default does not use third party cookies but you can enable a third party _pk_uid cookie it if you wish.

Learn more about What data does Matomo track?.

Default expiration times

The cookies described above will eventually expire and be removed from your users’ browsers. The default expiration times are listed below:

  • _pk_id – 13 months (used to store a few details about the user such as the unique visitor ID)
  • _pk_ref – 6 months (used to store the attribution information, the referrer initially used to visit the website)
  • _pk_ses, _pk_cvar, _pk_hsr – 30 minutes (short lived cookies used to temporarily store data for the visit)
  • _pk_testcookie is created and should be then directly deleted (used to check whether the visitor’s browser supports cookies)

These defaults can be modified via JavaScript. Learn more about setting custom expiration times.