The __stripe_mid cookie
A Stripe.js cookie holding a device identifier that helps Stripe assess the fraud risk of a payment.
__stripe_mid at a glance
- Cookie name
__stripe_mid- Vendor
- Stripe
- Category
- Security and fraud prevention
- Party
- First-party
- Typical duration
- 1 year
- Set on
.<your-domain>- Value format
- Opaque identifier, commonly UUID-like (format not documented by vendor)
- Name match
- Exactly
__stripe_mid
What the __stripe_mid cookie does
Stripe.js sets __stripe_mid for fraud prevention. It holds a device identifier that helps Stripe assess the risk of an attempted transaction, alongside the device and activity signals Stripe.js sends as part of Stripe's advanced fraud detection.
Stripe lists it with a 1 year lifetime and gives its domain as the site that loads Stripe.js, so it appears as a first-party cookie. It's usually found with __stripe_sid, which covers a single session.
What TagPipes observed
1.1%
of sites scanned set it (450 of 41,162)
365 days
median observed lifetime
TagPipes scanned 41,162 public websites between August 11, 2026 and September 13, 2026, loading up to three pages per site in a real browser as a first-time visitor. __stripe_mid was present on 450 of them.
It was set as a first-party cookie on 430 sites and as a third-party cookie on 20. A site can count in both. Where it was stored as a persistent cookie, the median lifetime we recorded was 365 days.
Often found alongside
- __stripe_sid 100%
- m 100%
- _ga 47%
- _ga_<container-id> 46%
- crumb 32%
- ss_cvr 31%
Percentage of sites with __stripe_mid where the other cookie was also present.
Technologies detected on the same sites
- Stripe on 100% of them (1.5% of all sites scanned)
- Google Fonts on 67% of them (78% of all sites scanned)
- Google Analytics on 62% of them (55% of all sites scanned)
- reCAPTCHA on 37% of them (32% of all sites scanned)
- Squarespace on 33% of them (23% of all sites scanned)
Aggregate figures across all sites scanned. Websites of TagPipes customers are excluded, no individual site is named, and cookie values are never read or stored. Snapshot dated September 13, 2026.
How to check for __stripe_mid on a website
- Open the site in Chrome, then open DevTools (F12, or Cmd+Option+I on a Mac).
- Go to the Application tab and expand Cookies in the left panel.
- Select each domain listed there and look for
__stripe_mid. The Expires column shows when it will be deleted. - If it is not there, reload the page. Many cookies are only set after a tag has loaded, and some only after a visitor has made a consent choice.
Other Stripe cookies
Sources
Purpose, duration and value format checked against the vendor documentation above on . The figures under What TagPipes observed are TagPipes scan data from September 13, 2026, not values documented by the vendor. Vendors change their cookies, and sites can configure their own names and lifetimes. Browse all cookies.
Know every cookie your own site sets
TagPipes Pulse identifies the cookies dropped on your site and flags unclassified or miscategorized ones. Shield builds your cookie declaration from a real scan rather than a questionnaire.
TagPipes monitors, configures and reports. It does not determine legal compliance and does not provide legal advice. Output is informational and reflects observed state at the time of observation. Rawsoft's expertise is technology, not law; please confirm any regulatory interpretation with your own counsel.