This page lists every cookie and browser storage key WebDecoy uses. It covers two different things, and the difference matters:

  • Our own sites, webdecoy.com, docs.webdecoy.com and the dashboard at app.webdecoy.com, where WebDecoy LLC decides what is set.
  • Sites that install WebDecoy, where our software runs on someone else's site. There the site owner decides, and this page is what they need in order to describe us accurately in their own policy.

1. Our marketing site (webdecoy.com)

NamePurposeLifetimeType
_ga, _ga_TE1MYSJJPVGoogle Analytics. Counts visits and tells us which pages are read2 yearsAnalytics
wd_hbSession storage. Stops our own bot detection script from sending more than one install check per browser tabUntil the tab closesNecessary

Our own bot detection script runs on this site, the same script customers install. We use our site as bait for crawlers on purpose.

2. Documentation (docs.webdecoy.com)

NamePurposeLifetimeType
_ga, _ga_TE1MYSJJPVGoogle Analytics, the same measurement as the marketing site2 yearsAnalytics
starlight-themeLocal storage. Remembers the documentation colour themeUntil you clear itFunctional

3. The dashboard (app.webdecoy.com)

No analytics or advertising runs in the dashboard. Everything below is first-party browser storage.

NamePurposeLifetimeType
@@auth0spajs@@…Keeps you signed in across tabsUntil you sign outNecessary
webdecoy_post_login_redirect, redirectAfterLoginReturns you to the page you asked for after signing inSeconds, during sign-inNecessary
wd.vercel.pendingInstallHolds a Vercel install handoff while you create an account25 minutesNecessary
webdecoy_selected_property_idRemembers which site you were looking atUntil you clear itFunctional
detections_burst_grouping, detections_burst_windowRemembers your detection table preferencesUntil you clear itFunctional
webdecoy.firstRunDismissed, webdecoy.firstRunExampleDecoyStops the getting-started banner reappearingUntil you clear it, and tab sessionFunctional
webdecoy.updateLanding, webdecoy.reloadedFor…Handles loading a new version of the app without a reload loopTab sessionNecessary
Offline cacheStores the app's own files so it loads fast and survives a deploy mid-sessionUntil replacedNecessary

The dashboard also loads a few things from other companies, which see your IP address and browser:

  • Auth0 handles sign-in and sets its own cookies on its domain during that redirect.
  • Google Fonts serves the typeface and icons.
  • jsDelivr serves the map outlines used by the geographic chart.
  • HubSpot loads the support form, and only when you open it. It may set its own cookies at that point.
  • Stripe handles checkout and billing on its own pages, where Stripe sets its own cookies.

4. What WebDecoy sets on sites that install it

If you are a visitor to a site protected by WebDecoy, this is everything our software puts in your browser. All of it is first-party to the site you are visiting. None of it is used for advertising, and none of it follows you to another site.

NamePurposeLifetimeWhere
wd_clearanceRecords that this browser already passed a check, so it is not challenged again on every page30 minutesSites using edge or client-side enforcement
webdecoy_verifiedThe same idea on WordPress: marks a visitor who passed the challenge15 minutesWordPress sites
wd_hbSession storage. One install check per tabTab sessionSites using the browser script
webdecoy_sessionSession storage. A random ID linking a shopping session to a detection, so a fraudulent order can be matched to what caused the alertTab sessionShopify stores

Worth stating plainly: the wd_clearance value is tied to a device signature calculated from your browser's rendering behaviour, screen and timezone. It exists to tell an automated client apart from a person, and it is what a block decision attaches to. We consider it strictly necessary for the security of the site you are visiting, and we would rather describe it than bury it.

Our server software, including the Node and PHP libraries, sets no cookies at all.

5. What we never do

  • No advertising or retargeting cookies, anywhere.
  • No session recording or replay.
  • No selling or sharing of personal information, under any state privacy law.
  • No tracking of individual people across unrelated sites. Our identifiers are per site.

6. Controlling cookies

We do not currently show a cookie banner on our own sites, so analytics on webdecoy.com and docs.webdecoy.com runs for everyone. You can stop it:

  • Install Google's Analytics opt-out add-on.
  • Block third-party or all cookies in your browser settings.
  • Use a browser or extension that blocks analytics by default.

Blocking cookies on our marketing site and documentation costs you nothing. Blocking them in the dashboard will prevent sign-in, because the sign-in session is kept in browser storage.

If you run a site with WebDecoy installed and need your visitors to be able to refuse wd_clearance, contact us. Enforcement can be run in a mode that reports without setting anything in the browser.

7. Questions

Email [email protected]. See also our Privacy Policy, our subprocessor list and our Data Processing Agreement.