TomasP
TomasP3mo ago

UserAgent cookie GDPR compliance

Currently, Zitadel uses two cookies: - zitadel.csrf - zitadel.useragent We understand that the zitadel.csrf cookie is required to ensure a secure login flow. However, the second cookie appears to be used for session storage. Are you considering this cookie to be required or functional? If it is functional (i.e., optional), it should be possible to prevent its creation to ensure Zitadel remains GDPR compliant. Could you please clarify this for us? (Perhaps you classify this cookie as required.) Thank you!
4 Replies
TomasP
TomasPOP3mo ago
Can anyone from Zitadel team help me here, just to clear things up?
Raccine
Raccine3mo ago
Hey @TomasP! Thanks for reaching out. Let me escalate this internally to get you some more context on if this cookie is required or optional and I'll get back to you as soon as possible. ☺️ Are you currently using your own custom login or are you using our out-of-the-box login?
TomasP
TomasPOP2mo ago
We are using the out-of-the-box Zitadel login UI. Hi, any updates on the cookie situation?
Rajat
Rajat2mo ago
hey @TomasP based on internal discussion, when using our login it’s needed

Did you find this page helpful?