Shield · Cookies

Cookies

FindIP Shield stores two random IDs in the visitor's browser, both first-party and containing no personal data: a session ID and a visitor ID. The visitor ID is also kept in localStorage.

_fip_sid

Session

PurposeSession continuity
Duration30 minutes (rolling)
ValueRandom opaque ID, e.g. sess_abcd1234
ContainsNo IP, email, or personal data

_fip_vid

Visitor

PurposeRepeat visitor detection
Duration7–30 days (configurable)
Disabled instrict privacy mode
ValueRandom opaque ID, e.g. vis_abcd1234
Also stored inlocalStorage, key _fip_vid (SDK 1.11.0 and later)

When cookies are blocked

Fallback order

Session ID

1sessionStorage
2The tab's window.name (SDK 1.11.0 and later): _fip_sid=<site key>.<session id>.<last seen>. It expires like the session cookie, is tied to your site key, and ends with the tab. The SDK only writes an empty window.name and removes its value once the cookie works again.
3A link token, only when you switch on linkSession (SDK 1.11.0 and later): at click time the SDK adds _fip=<session id>.<time> to same-origin links, and the page that opens removes it from the address bar. It is accepted for two minutes and only on a page reached from the same origin. Your server sees the parameter on that one request.
4In-memory session ID, for the current page only
5When nothing in the browser keeps the ID, Shield derives one for the visit from the request (IP address, browser and language, for one UTC day). Nothing is stored in the browser for this.

Visitor ID

1localStorage (not in strict mode)
2When neither can be written, the SDK sends no visitor ID and Shield derives one the same way, except in strict mode.

Sessions from such browsers are marked "Cookies blocked" in the dashboard. The SDK continues working without cookies.

The localStorage copy of the visitor ID

SDK 1.11.0 and later

The visitor ID is kept in two places with the same lifetime: the _fip_vid cookie and a localStorage entry of the same name. On each page the SDK reads whichever still holds the ID, the cookie first, and writes both again. A visitor whose cookie was removed, or whose browser refuses the cookie, keeps the same visitor ID as long as the localStorage entry is there.

Clearing site dataRemoves both and starts a new visitor.
Strict modeNeither is written or read.
Consent withdrawnWhen a visitor who had agreed withdraws consent (FindIP.setConsent(false) after an earlier grant), the SDK deletes both and stops sending the visitor ID.

If your cookie notice lists the storage your site uses, list the _fip_vid localStorage entry next to the cookie.

Configuration & troubleshooting

FindIP.init({
  sessionCookieDurationMinutes: 30,
  visitorCookieDurationDays: 30,
});
No _fip_vid in strict modeExpected behavior, for the cookie and the localStorage entry.
sess_cl_… or vis_cl_… IDsDerived by Shield for a browser that keeps nothing.
_fip_sid missingCheck browser privacy settings — the sessionStorage fallback still works.