Cloudflare will stop sending the __cfduid cookie on May 10, 2021. From that date, no new Set-Cookie headers will be added to HTTP responses, and any existing __cfduid cookies will expire 30 days later.

The departure is partly a matter of perception. Despite the "uid" in its name, the cookie was never a user identifier, and Cloudflare states it has never tracked end users across sites or sold personal data. Still, the company wants to eliminate any ambiguity about its cookie usage and remove the possibility that customers feel compelled to show a cookie consent banner because of Cloudflare's technology.

The __cfduid cookie served one primary function: bot detection. Malicious automated traffic can disrupt services through DDoS attacks or compromise accounts via brute-force password cracking and credential stuffing. Cloudflare's machine learning models were trained on a range of signals, and the presence and age of this cookie was just one input among many.

The cookie's value was generated from a one-way MD5 hash combining the IP address, date and time, user agent, hostname, and referring website. That design meant the cookie could not be tied to a specific person. Nevertheless, Cloudflare has been testing whether its bot detection can run without collecting end-user IP addresses in this way, and the company says the transition is feasible.

Transition timeline and caveats

The deprecation notice is being issued early to give customers time to adjust. Cloudflare's bot management team is working to ensure detection quality does not decline after the cookie is removed. Some customers using Bot Management products may continue to need a separate, different cookie after April 1, but that requirement is unrelated to __cfduid.