Skip to main content
Cookie reference · Hotjar

The _hjSessionUser_<site-id> cookie

The Hotjar user cookie, which keeps a site-specific Hotjar user ID so repeat visits are tied together.

_hjSessionUser_<site-id> at a glance

Cookie name
_hjSessionUser_<site-id>
Vendor
Hotjar
Category
Analytics
Party
First-party
Typical duration
365 days
Set on
.<your-domain>
Value format
JSON (fields not documented by vendor)
Name match
Any cookie whose name starts with _hjSessionUser_

What the _hjSessionUser_<site-id> cookie does

Hotjar sets _hjSessionUser_ when a visitor first lands on a page, with the site's Hotjar ID as the suffix. It persists the Hotjar user ID, which is unique to that site, so data from later visits to the same site is attributed to the same user.

Hotjar documents a 365 day lifetime and says the ID doesn't track users across different sites. It's paired with _hjSession_, which covers the current session.

What TagPipes observed

0.47%

of sites scanned set it (192 of 41,162)

365 days

median observed lifetime

TagPipes scanned 41,162 public websites between August 11, 2026 and September 13, 2026, loading up to three pages per site in a real browser as a first-time visitor. _hjSessionUser_<site-id> was present on 192 of them.

It was set as a first-party cookie on 176 sites and as a third-party cookie on 16. A site can count in both. Where it was stored as a persistent cookie, the median lifetime we recorded was 365 days.

Often found alongside

Percentage of sites with _hjSessionUser_<site-id> where the other cookie was also present.

Technologies detected on the same sites

  • Hotjar on 100% of them (0.49% of all sites scanned)
  • Google Analytics on 97% of them (55% of all sites scanned)
  • Google Fonts on 77% of them (78% of all sites scanned)
  • Google Tag Manager on 73% of them (30% of all sites scanned)
  • Meta Pixel on 66% of them (13% of all sites scanned)

Aggregate figures across all sites scanned. Websites of TagPipes customers are excluded, no individual site is named, and cookie values are never read or stored. Snapshot dated September 13, 2026.

How to check for _hjSessionUser_<site-id> on a website

  1. Open the site in Chrome, then open DevTools (F12, or Cmd+Option+I on a Mac).
  2. Go to the Application tab and expand Cookies in the left panel.
  3. Select each domain listed there and look for a name starting with _hjSessionUser_. The Expires column shows when it will be deleted.
  4. If it is not there, reload the page. Many cookies are only set after a tag has loaded, and some only after a visitor has made a consent choice.

Sources

Purpose, duration and value format checked against the vendor documentation above on . The figures under What TagPipes observed are TagPipes scan data from September 13, 2026, not values documented by the vendor. Vendors change their cookies, and sites can configure their own names and lifetimes. Browse all cookies.

Know every cookie your own site sets

TagPipes Pulse identifies the cookies dropped on your site and flags unclassified or miscategorized ones. Shield builds your cookie declaration from a real scan rather than a questionnaire.

TagPipes monitors, configures and reports. It does not determine legal compliance and does not provide legal advice. Output is informational and reflects observed state at the time of observation. Rawsoft's expertise is technology, not law; please confirm any regulatory interpretation with your own counsel.