Cookie syncing, also called cookie matching or user syncing, is the process by which two advertising technology companies learn that their separate identifiers belong to the same browser. It exists because a cookie can be read only by the domain that set it. An exchange sees its own cookie, a demand-side platform (DSP) sees its own, and neither can read the other's. Without a translation, a DSP receiving a bid request cannot tell whether the browser behind it belongs to an audience it has built or to someone already shown the same ad five times that day.
OpenRTB, the IAB Tech Lab's bidding specification, calls the process "foundational to availability of IDs in the cookie-based web environment". Its output is a match table recording, in the specification's example, that cookieID123 from party A is the same user as cookieID789 from party B.
How a sync works
A sync pixel, usually a 1x1 image or an iframe, loads while a page renders or an ad serves. The first company's server reads its cookie, or sets one, and answers with an HTTP 302 redirect to a partner URL carrying its user ID in the query string. When the browser follows the redirect, the partner reads its own cookie on its own domain and now holds both values.
In the exchange-hosted model, most common between DSPs and supply-side platforms (SSPs), the exchange looks up its cookie when an ad request arrives and writes the DSP's identifier into the buyeruid field of the outgoing bid request. In the DSP-hosted model, the exchange sends its own ID in user.id and the buyer translates it. OpenRTB 2.6 defines buyeruid as the "buyer-specific ID for the user as mapped by the exchange for the buyer", a value that, absent prior arrangements, "is expected to be derived from an ID sync". It sits in the user object of the bid request beside third-party identifiers and the consent string.
Google's Authorized Buyers documentation shows the plumbing at scale. A bidder's tag calls cm.g.doubleclick.net with its account identifier in a google_nid parameter, and Google redirects back with a bidder-specific user ID in google_gid. Alternatively Google hosts the table, storing up to 40 bytes of the buyer's data and returning it as buyeruid. Hosted records may be treated as stale after 14 days, and matching is throttled for bidders answering fewer than 90% of requests. For users in US states with privacy restrictions, Google omits its user ID from bid requests altogether.
Header bidding moved much of the activity onto publisher pages. Prebid.js lets each bidder adapter fire up to five sync pixels by default, three seconds after the auction, with images permitted and iframes blocked unless enabled, according to Prebid documentation. Equativ's adapter syncs through iframes rather than image pixels, so leaving that setting off degrades its matching.
A server cannot read browser cookies, so Prebid Server keeps its own uids cookie, populated through /cookie_sync and /setuid endpoints, and treats entries as stale after seven days. Index Exchange's documentation concedes that its browser adapter matches better than its server route. Mobile apps and connected television have no browser cookies to reconcile; buyers there read the device's resettable advertising identifier directly.
Origin and evolution
Cookie matching arrived with real-time bidding (RTB). Google unveiled a rebuilt DoubleClick Ad Exchange with real-time bidding in September 2009, and a Google white paper from July 2011 recorded RTB's share on the exchange rising from 8% in January 2010 to 68% by May 2011. OpenRTB 2.0, released in January 2012, already carried buyeruid, defined as the "buyer's user ID for this user as mapped by exchange for the buyer".
Researchers soon measured the consequences. Lukasz Olejnik, Minh-Dung Tran and Claude Castelluccia told the NDSS symposium in February 2014 that elements of browsing histories were "routinely being sold off for less than $0.0005" through RTB and cookie matching. A 2016 study of one million websites by Steven Englehardt and Arvind Narayanan found 460 of the top 1,000 third parties syncing, with doubleclick.net alone sharing 108 cookies with 118 others. In 2019 Panagiotis Papadopoulos, Nicolas Kourtellis and Evangelos Markatos, analysing a year of logs from 850 mobile users, reported that 97% of regular web users were exposed and that syncing multiplied the domains tracking each user by 6.75.
Browsers then removed the raw material. Apple introduced Intelligent Tracking Prevention (ITP) in 2017 and blocked all third-party cookies in Safari from March 24, 2020. Firefox blocked known tracking cookies by default from September 3, 2019, and from June 14, 2022 gave every site a separate "cookie jar", according to Mozilla. Google announced on January 14, 2020 that Chrome's third-party cookies would go within two years, restricted them for 1% of users in January 2024, switched to a user-choice plan on July 22, 2024 and dropped the standalone prompt on April 22, 2025. On October 17, 2025 it retired most Privacy Sandbox technologies, keeping CHIPS, FedCM and Private State Tokens.
The specification caught up late. IAB Tech Lab opened changes for public comment on May 8, 2024 after, according to Sincera's Mike O'Sullivan, "many buyers were surprised to learn" that buyeruid values "no longer exclusively represented the result of a single, 1:1 cookie sync". The update of September 23, 2024 added a three-page definition of cookie syncing and three provenance attributes on the extended identifiers (eids) object: inserter, matcher and mm. Match method 2 is reserved for "Browser Cookie Sync", so buyers can see whether an identifier was observed directly, produced by a sync or bridged by a graph.
Why it matters
For sellers, recognition pays. BidSwitch data for 2019 found impressions not matched through cookies selling at eCPMs a third of those using cookie syncing, with matched SSP requests drawing bid rates 57% higher. A Google study that year found cookieless traffic yielded 52% less publisher revenue on average. For buyers, the synced ID underpins the uses OpenRTB lists for it: audience targeting, frequency capping and measurement.
Each handoff loses signal. Equativ's October 2024 analysis put match rate losses between platforms at 40% to 70%, compounding with every third-party sync, an argument SSPs have used to move audience targeting onto the sell side. Cloudflare data for the third quarter of 2025 put Chrome at 66.3% of global browser traffic, Safari at 15.1% and Firefox at 3.8%, and reach metrics built on syncs drop Safari and app audiences entirely.
Limitations and disputes
Privacy is the oldest objection. Each sync hands a persistent identifier to another company, unseen by the user. In September 2019 Johnny Ryan, then at Brave, filed evidence with Ireland's Data Protection Commission stating that google_gid identifiers were used 318 times in network traffic from ten companies during one hour of browsing, routed through Google "push pages". Google said at the time that it did not serve personalised ads or send bid requests without user consent, according to MediaPost.
Courts are now involved. The In re Google RTB Consumer Privacy Litigation settlement, given final approval on March 26, 2026, requires a user control that strips encrypted Google user IDs, device advertising IDs, IP addresses and cookie-matching data from bid requests. McGrath v. Google, filed on February 19, 2026, alleges that Google transmitted its identifier to Pangle, MediaGo and Temu through cookie syncing on sites including Drugs.com. Those claims remain untested.
Consent now gates the pixel itself. Under the Transparency and Consent Framework (TCF), Google syncs with vendors only when consent for Purposes 1, 3 and 4 and legitimate interest for Purposes 2, 7, 9 and 10 are present.
Publishers raise a commercial objection: a buyer that recognises a premium publisher's audience can target the same people on cheaper sites. A 2012 Google Research paper by Arpita Ghosh, Mohammad Mahdian, R. Preston McAfee and Sergei Vassilvitskii named this information leakage and showed that, when advertisers are not homogeneous, it can help one publisher and harm another.
The sharpest dispute concerns what a synced field contains. ID bridging filled buyeruid with identifiers derived by other methods, leaving buyers unable to tell a deterministic browser match from an inference. The 2024 provenance fields made that difference declarable. They did not make declaring it mandatory.
Not the same as
Match rate is a metric, the share of records or requests resolving to a known identifier. Cookie syncing is one mechanism behind it; list uploads and clean rooms are others.
ID bridging fills buyeruid or eids with an identifier obtained another way, such as a hashed email address or an IP-based inference.
A device graph links several devices to one person or household, whereas cookie syncing matches two vendors' identifiers for one browser.
Universal IDs such as UID2, ID5 and RampID replace pairwise syncing with one shared string carried in the eids array.
Recent developments
Google discontinued Cookie Match Assist, which fired pixels to help SSPs sync with their DSP partners, on October 28, 2025, according to its developer documentation. Its deadline for TCF v2.3 consent strings followed on February 28, 2026.
Legislators are now naming the pixel. Australia's Privacy Amendment (Personal Data Protection) Bill 2026, opened for consultation on August 31, 2026, would treat "disclosures of cookies or pixels in programmatic advertising processes" as trades requiring consent. Standards are tightening too: IAB Tech Lab's Programmatic Best Practices v1.0, released for public comment on September 16, 2026, prohibits silent identifier bridging and requires its buyeruid guidance to be followed. Comments close on October 16, 2026.
Chrome, with about two-thirds of global browser traffic, still permits third-party cookies by default, so the pixel-and-redirect routine keeps running while the list of what may pass through it shrinks.
Timeline
- September 2009: Google unveils a rebuilt DoubleClick Ad Exchange with real-time bidding
- January 2012: OpenRTB 2.0 is released with the buyeruid attribute in the user object
- February 2014: Olejnik, Tran and Castelluccia present research on RTB and cookie matching at NDSS
- 2016: Englehardt and Narayanan's one-million-site study counts 460 of the top 1,000 third parties syncing
- June 5, 2017: Apple announces Intelligent Tracking Prevention for Safari
- September 2, 2019: Brave's Johnny Ryan submits push-page evidence to the Irish Data Protection Commission
- September 3, 2019: Firefox begins blocking third-party tracking cookies by default
- January 14, 2020: Google announces plans to phase out third-party cookies in Chrome within two years
- March 24, 2020: Safari blocks all third-party cookies by default
- March 26, 2021: In re Google RTB Consumer Privacy Litigation complaint is filed
- June 14, 2022: Firefox makes Total Cookie Protection the default for all users
- January 4, 2024: Chrome restricts third-party cookies for 1% of users
- May 8, 2024: IAB Tech Lab opens buyeruid and identifier provenance changes for public comment
- July 22, 2024: Google replaces cookie deprecation with a user-choice plan
- September 23, 2024: OpenRTB update adds a cookie syncing definition and eids provenance attributes
- October 2024: Equativ puts match rate losses between platforms at 40% to 70%
- April 22, 2025: Google drops the planned standalone third-party cookie prompt
- October 17, 2025: Google retires most Privacy Sandbox technologies
- October 28, 2025: Google discontinues Cookie Match Assist
- February 19, 2026: McGrath v. Google is filed in the Northern District of California
- February 28, 2026: Google ends support for new TCF v2.2 strings
- March 26, 2026: Final approval of the Google RTB settlement requiring a control that strips cookie-matching data
- August 31, 2026: Australia opens consultation on a bill treating cookie and pixel disclosures as trades
- September 16, 2026: IAB Tech Lab releases Programmatic Best Practices v1.0 for public comment
Related PPC Land coverage
- Explaining bidstream - The fields carried in an OpenRTB bid request, including the buyeruid produced by syncing.
- Explaining match rate - How match percentages are produced across list uploads, cookie synchronisation, audience platforms and clean rooms.
- Explaining Equativ - The SSP whose Prebid adapter syncs through iframes and whose curation analysis quantified match loss.
- Explaining server-side - Why moving auctions and tags to servers costs identity, and how Prebid Server keeps its own synced IDs.
- Apple starts blocking all third-party cookies in Safari - The 2020 WebKit change that ended cookie syncing in Safari by default.
- Google Chrome to kill third-party cookies within 2 years - The January 2020 Privacy Sandbox announcement that set the original deprecation timetable.
- Chrome begins phasing out third-party cookies - The January 2024 restriction applied to 1% of Chrome users.
- Google unveils new path for Privacy Sandbox: user choice takes center stage - The July 2024 decision to replace deprecation with a user choice.
- Google keeps cookies - The April 2025 announcement that Chrome would not roll out a standalone third-party cookie prompt.
- Chrome kills most Privacy Sandbox technologies after adoption fails - Which Privacy Sandbox APIs were retired in October 2025 and which survived.
- Explaining unlinkability - Why identifiers that link records are contested, and how OpenRTB now records the provenance of each one.
- Cookieless ad impressions are one-third cheaper, BidSwitch finds - Price and bid-rate differences between synced and unsynced impressions in 2019 data.
- Why SSPs are leading the programmatic market through supply path curation - Equativ's analysis of match rate losses of 40% to 70% between platforms.
- Explaining addressable reach - How reach counts built on cookie syncs exclude Safari and app audiences.
- Judge approves Google RTB settlement forcing new user privacy control - The settlement requiring a control that removes Google user IDs and cookie-matching data from bid requests.
- Google sued over RTB data transfers to Baidu, ByteDance, and Temu - A 2026 complaint alleging identifier transfers to foreign-owned companies through cookie syncing.
- Google mandates TCF v2.3 migration by February 2026 - The consent purposes Google requires before syncing cookies with vendors.
- Explaining device graph - How cross-device graphs differ from single-browser cookie syncs.
- Australia would force ad tech to get consent before sharing pixels - A proposed privacy bill treating cookie and pixel disclosures as trades that need consent.
- IAB Tech Lab sets rules to curb duplicate ad bid requests industry-wide - Draft best practices that ban silent identifier bridging and enforce buyeruid guidance.
Summary
Who. Exchanges, supply-side platforms and demand-side platforms run cookie syncs, alongside data management platforms and header bidding wrappers such as Prebid. IAB Tech Lab defines how the result travels in OpenRTB; browser makers, regulators and courts set the limits.
What. Cookie syncing maps one company's cookie ID for a browser to another company's ID for the same browser, using a pixel and an HTTP redirect, and stores the pair in a match table. The mapped value typically reaches the buyer in the buyeruid field of a bid request.
When. The practice took hold with real-time bidding from 2009, was reflected in OpenRTB 2.0 in January 2012, was formally defined in the specification in September 2024, and has been curtailed by default in Firefox since 2019 and in Safari since 2020.
Where. It runs in web browsers, on publisher pages, in ad calls and in server-side auction infrastructure. It does not operate in mobile apps or connected television, which rely on device advertising identifiers instead.
Why. Browsers confine cookies to the domain that set them, so buyers cannot otherwise recognise users inside bid requests. Recognition supports targeting, frequency capping and measurement, and lifts prices for sellers, but each sync leaks identifiers across companies and loses part of the signal along the way.
Discussion