Cookie syncing, also called cookie matching or user syncing, is the process by which two advertising technology companies learn that their separate identifiers belong to the same browser. It exists because a cookie can be read only by the domain that set it. An exchange sees its own cookie, a demand-side platform (DSP) sees its own, and neither can read the other's. Without a translation, a DSP receiving a bid request cannot tell whether the browser behind it belongs to an audience it has built or to someone already shown the same ad five times that day.

OpenRTB, the IAB Tech Lab's bidding specification, calls the process "foundational to availability of IDs in the cookie-based web environment". Its output is a match table recording, in the specification's example, that cookieID123 from party A is the same user as cookieID789 from party B.

How a sync works

A sync pixel, usually a 1x1 image or an iframe, loads while a page renders or an ad serves. The first company's server reads its cookie, or sets one, and answers with an HTTP 302 redirect to a partner URL carrying its user ID in the query string. When the browser follows the redirect, the partner reads its own cookie on its own domain and now holds both values.

In the exchange-hosted model, most common between DSPs and supply-side platforms (SSPs), the exchange looks up its cookie when an ad request arrives and writes the DSP's identifier into the buyeruid field of the outgoing bid request. In the DSP-hosted model, the exchange sends its own ID in user.id and the buyer translates it. OpenRTB 2.6 defines buyeruid as the "buyer-specific ID for the user as mapped by the exchange for the buyer", a value that, absent prior arrangements, "is expected to be derived from an ID sync". It sits in the user object of the bid request beside third-party identifiers and the consent string.

Google's Authorized Buyers documentation shows the plumbing at scale. A bidder's tag calls cm.g.doubleclick.net with its account identifier in a google_nid parameter, and Google redirects back with a bidder-specific user ID in google_gid. Alternatively Google hosts the table, storing up to 40 bytes of the buyer's data and returning it as buyeruid. Hosted records may be treated as stale after 14 days, and matching is throttled for bidders answering fewer than 90% of requests. For users in US states with privacy restrictions, Google omits its user ID from bid requests altogether.

Header bidding moved much of the activity onto publisher pages. Prebid.js lets each bidder adapter fire up to five sync pixels by default, three seconds after the auction, with images permitted and iframes blocked unless enabled, according to Prebid documentation. Equativ's adapter syncs through iframes rather than image pixels, so leaving that setting off degrades its matching.

A server cannot read browser cookies, so Prebid Server keeps its own uids cookie, populated through /cookie_sync and /setuid endpoints, and treats entries as stale after seven days. Index Exchange's documentation concedes that its browser adapter matches better than its server route. Mobile apps and connected television have no browser cookies to reconcile; buyers there read the device's resettable advertising identifier directly.

Origin and evolution

Cookie matching arrived with real-time bidding (RTB). Google unveiled a rebuilt DoubleClick Ad Exchange with real-time bidding in September 2009, and a Google white paper from July 2011 recorded RTB's share on the exchange rising from 8% in January 2010 to 68% by May 2011. OpenRTB 2.0, released in January 2012, already carried buyeruid, defined as the "buyer's user ID for this user as mapped by exchange for the buyer".

Researchers soon measured the consequences. Lukasz Olejnik, Minh-Dung Tran and Claude Castelluccia told the NDSS symposium in February 2014 that elements of browsing histories were "routinely being sold off for less than $0.0005" through RTB and cookie matching. A 2016 study of one million websites by Steven Englehardt and Arvind Narayanan found 460 of the top 1,000 third parties syncing, with doubleclick.net alone sharing 108 cookies with 118 others. In 2019 Panagiotis Papadopoulos, Nicolas Kourtellis and Evangelos Markatos, analysing a year of logs from 850 mobile users, reported that 97% of regular web users were exposed and that syncing multiplied the domains tracking each user by 6.75.

Browsers then removed the raw material. Apple introduced Intelligent Tracking Prevention (ITP) in 2017 and blocked all third-party cookies in Safari from March 24, 2020. Firefox blocked known tracking cookies by default from September 3, 2019, and from June 14, 2022 gave every site a separate "cookie jar", according to Mozilla. Google announced on January 14, 2020 that Chrome's third-party cookies would go within two years, restricted them for 1% of users in January 2024, switched to a user-choice plan on July 22, 2024 and dropped the standalone prompt on April 22, 2025. On October 17, 2025 it retired most Privacy Sandbox technologies, keeping CHIPS, FedCM and Private State Tokens.

The specification caught up late. IAB Tech Lab opened changes for public comment on May 8, 2024 after, according to Sincera's Mike O'Sullivan, "many buyers were surprised to learn" that buyeruid values "no longer exclusively represented the result of a single, 1:1 cookie sync". The update of September 23, 2024 added a three-page definition of cookie syncing and three provenance attributes on the extended identifiers (eids) object: inserter, matcher and mm. Match method 2 is reserved for "Browser Cookie Sync", so buyers can see whether an identifier was observed directly, produced by a sync or bridged by a graph.

Why it matters

For sellers, recognition pays. BidSwitch data for 2019 found impressions not matched through cookies selling at eCPMs a third of those using cookie syncing, with matched SSP requests drawing bid rates 57% higher. A Google study that year found cookieless traffic yielded 52% less publisher revenue on average. For buyers, the synced ID underpins the uses OpenRTB lists for it: audience targeting, frequency capping and measurement.

Each handoff loses signal. Equativ's October 2024 analysis put match rate losses between platforms at 40% to 70%, compounding with every third-party sync, an argument SSPs have used to move audience targeting onto the sell side. Cloudflare data for the third quarter of 2025 put Chrome at 66.3% of global browser traffic, Safari at 15.1% and Firefox at 3.8%, and reach metrics built on syncs drop Safari and app audiences entirely.

Limitations and disputes

Privacy is the oldest objection. Each sync hands a persistent identifier to another company, unseen by the user. In September 2019 Johnny Ryan, then at Brave, filed evidence with Ireland's Data Protection Commission stating that google_gid identifiers were used 318 times in network traffic from ten companies during one hour of browsing, routed through Google "push pages". Google said at the time that it did not serve personalised ads or send bid requests without user consent, according to MediaPost.

Courts are now involved. The In re Google RTB Consumer Privacy Litigation settlement, given final approval on March 26, 2026, requires a user control that strips encrypted Google user IDs, device advertising IDs, IP addresses and cookie-matching data from bid requests. McGrath v. Google, filed on February 19, 2026, alleges that Google transmitted its identifier to Pangle, MediaGo and Temu through cookie syncing on sites including Drugs.com. Those claims remain untested.

Consent now gates the pixel itself. Under the Transparency and Consent Framework (TCF), Google syncs with vendors only when consent for Purposes 1, 3 and 4 and legitimate interest for Purposes 2, 7, 9 and 10 are present.

Publishers raise a commercial objection: a buyer that recognises a premium publisher's audience can target the same people on cheaper sites. A 2012 Google Research paper by Arpita Ghosh, Mohammad Mahdian, R. Preston McAfee and Sergei Vassilvitskii named this information leakage and showed that, when advertisers are not homogeneous, it can help one publisher and harm another.

The sharpest dispute concerns what a synced field contains. ID bridging filled buyeruid with identifiers derived by other methods, leaving buyers unable to tell a deterministic browser match from an inference. The 2024 provenance fields made that difference declarable. They did not make declaring it mandatory.

Not the same as

Match rate is a metric, the share of records or requests resolving to a known identifier. Cookie syncing is one mechanism behind it; list uploads and clean rooms are others.

ID bridging fills buyeruid or eids with an identifier obtained another way, such as a hashed email address or an IP-based inference.

A device graph links several devices to one person or household, whereas cookie syncing matches two vendors' identifiers for one browser.

Universal IDs such as UID2, ID5 and RampID replace pairwise syncing with one shared string carried in the eids array.

Recent developments

Google discontinued Cookie Match Assist, which fired pixels to help SSPs sync with their DSP partners, on October 28, 2025, according to its developer documentation. Its deadline for TCF v2.3 consent strings followed on February 28, 2026.

Legislators are now naming the pixel. Australia's Privacy Amendment (Personal Data Protection) Bill 2026, opened for consultation on August 31, 2026, would treat "disclosures of cookies or pixels in programmatic advertising processes" as trades requiring consent. Standards are tightening too: IAB Tech Lab's Programmatic Best Practices v1.0, released for public comment on September 16, 2026, prohibits silent identifier bridging and requires its buyeruid guidance to be followed. Comments close on October 16, 2026.

Chrome, with about two-thirds of global browser traffic, still permits third-party cookies by default, so the pixel-and-redirect routine keeps running while the list of what may pass through it shrinks.

Timeline

  • September 2009: Google unveils a rebuilt DoubleClick Ad Exchange with real-time bidding
  • January 2012: OpenRTB 2.0 is released with the buyeruid attribute in the user object
  • February 2014: Olejnik, Tran and Castelluccia present research on RTB and cookie matching at NDSS
  • 2016: Englehardt and Narayanan's one-million-site study counts 460 of the top 1,000 third parties syncing
  • June 5, 2017: Apple announces Intelligent Tracking Prevention for Safari
  • September 2, 2019: Brave's Johnny Ryan submits push-page evidence to the Irish Data Protection Commission
  • September 3, 2019: Firefox begins blocking third-party tracking cookies by default
  • January 14, 2020: Google announces plans to phase out third-party cookies in Chrome within two years
  • March 24, 2020: Safari blocks all third-party cookies by default
  • March 26, 2021: In re Google RTB Consumer Privacy Litigation complaint is filed
  • June 14, 2022: Firefox makes Total Cookie Protection the default for all users
  • January 4, 2024: Chrome restricts third-party cookies for 1% of users
  • May 8, 2024: IAB Tech Lab opens buyeruid and identifier provenance changes for public comment
  • July 22, 2024: Google replaces cookie deprecation with a user-choice plan
  • September 23, 2024: OpenRTB update adds a cookie syncing definition and eids provenance attributes
  • October 2024: Equativ puts match rate losses between platforms at 40% to 70%
  • April 22, 2025: Google drops the planned standalone third-party cookie prompt
  • October 17, 2025: Google retires most Privacy Sandbox technologies
  • October 28, 2025: Google discontinues Cookie Match Assist
  • February 19, 2026: McGrath v. Google is filed in the Northern District of California
  • February 28, 2026: Google ends support for new TCF v2.2 strings
  • March 26, 2026: Final approval of the Google RTB settlement requiring a control that strips cookie-matching data
  • August 31, 2026: Australia opens consultation on a bill treating cookie and pixel disclosures as trades
  • September 16, 2026: IAB Tech Lab releases Programmatic Best Practices v1.0 for public comment

Summary

Who. Exchanges, supply-side platforms and demand-side platforms run cookie syncs, alongside data management platforms and header bidding wrappers such as Prebid. IAB Tech Lab defines how the result travels in OpenRTB; browser makers, regulators and courts set the limits.

What. Cookie syncing maps one company's cookie ID for a browser to another company's ID for the same browser, using a pixel and an HTTP redirect, and stores the pair in a match table. The mapped value typically reaches the buyer in the buyeruid field of a bid request.

When. The practice took hold with real-time bidding from 2009, was reflected in OpenRTB 2.0 in January 2012, was formally defined in the specification in September 2024, and has been curtailed by default in Firefox since 2019 and in Safari since 2020.

Where. It runs in web browsers, on publisher pages, in ad calls and in server-side auction infrastructure. It does not operate in mobile apps or connected television, which rely on device advertising identifiers instead.

Why. Browsers confine cookies to the domain that set them, so buyers cannot otherwise recognise users inside bid requests. Recognition supports targeting, frequency capping and measurement, and lifts prices for sellers, but each sync leaks identifiers across companies and loses part of the signal along the way.