The _ga cookie
The main Google Analytics cookie: it stores a random client ID so Google Analytics can tell one browser from another across visits.
_ga at a glance
- Cookie name
_ga- Vendor
- Google Analytics
- Category
- Analytics
- Party
- First-party
- Typical duration
- 2 years
- Set on
.<your-domain>- Value format
GA1.<domain-level>.<random-number>.<first-visit-timestamp>- Name match
- Exactly
_ga
What the _ga cookie does
The Google tag creates _ga the first time a browser loads a page with Google Analytics on it. The value holds a randomly generated client ID and the time of that first visit, and the ID is sent with every hit so visits from the same browser can be tied together over time.
It's a first-party cookie, written to the highest-level domain the tag can use, so subdomains of the same site share it. Google documents a default lifetime of 2 years, and a GA4 property can override both the expiry and whether it's refreshed on each visit. The GA1 value structure is widely observed but isn't spelled out in Google's current documentation.
What TagPipes observed
50%
of sites scanned set it (20,680 of 41,162)
400 days
median observed lifetime
TagPipes scanned 41,162 public websites between August 11, 2026 and September 13, 2026, loading up to three pages per site in a real browser as a first-time visitor. _ga was present on 20,680 of them.
It was set as a first-party cookie on 20,324 sites and as a third-party cookie on 528. A site can count in both. Where it was stored as a persistent cookie, the median lifetime we recorded was 400 days, and it was a session cookie on 3 sites. Chrome limits any cookie to 400 days, so a longer lifetime set by the vendor shows up as about 13 months in Chrome.
Often found alongside
Percentage of sites with _ga where the other cookie was also present.
Technologies detected on the same sites
- Google Analytics on 100% of them (55% of all sites scanned)
- Google Fonts on 89% of them (78% of all sites scanned)
- Google Tag Manager on 55% of them (30% of all sites scanned)
- reCAPTCHA on 26% of them (32% of all sites scanned)
- DoubleClick on 20% of them (11% of all sites scanned)
Aggregate figures across all sites scanned. Websites of TagPipes customers are excluded, no individual site is named, and cookie values are never read or stored. Snapshot dated September 13, 2026.
How to check for _ga on a website
- Open the site in Chrome, then open DevTools (F12, or Cmd+Option+I on a Mac).
- Go to the Application tab and expand Cookies in the left panel.
- Select each domain listed there and look for
_ga. The Expires column shows when it will be deleted. - If it is not there, reload the page. Many cookies are only set after a tag has loaded, and some only after a visitor has made a consent choice.
Other Google Analytics cookies
Sources
- Google Analytics Help: Google Analytics cookie usage on websites
- Google: Cookies used by Google advertising and measurement products
Purpose, duration and value format checked against the vendor documentation above on . The figures under What TagPipes observed are TagPipes scan data from September 13, 2026, not values documented by the vendor. Vendors change their cookies, and sites can configure their own names and lifetimes. Browse all cookies.
Know every cookie your own site sets
TagPipes Pulse identifies the cookies dropped on your site and flags unclassified or miscategorized ones. Shield builds your cookie declaration from a real scan rather than a questionnaire.
TagPipes monitors, configures and reports. It does not determine legal compliance and does not provide legal advice. Output is informational and reflects observed state at the time of observation. Rawsoft's expertise is technology, not law; please confirm any regulatory interpretation with your own counsel.