Cookie Policy
NOTEDWhat changed, in plain language
GitHub added one new first-party cookie to its cookie list: `notifications_web_disabled`, which remembers for one month whether you've turned off web notifications so the site doesn't have to look it up each time. Nothing else changed — no new tracking, no new third-party sharing, and no change to your cookie choices.
Changelog
- + ADDEDNew GitHub cookie added for notification settings
GitHub now lists a cookie called `notifications_web_disabled`. It simply remembers whether you have web notifications turned off, so the notifications icon in the top navigation bar loads faster. It is set by GitHub itself (not an outside company), it stores a setting rather than tracking your browsing, and it lasts one month.
| GitHub | `notifications_web_disabled` | This cookie caches whether web notifications are disabled, so the global navigation notifications indicator can be rendered without an additional lookup. | One month |
Full text changes
COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED
| 21 | 21 | | GitHub | `has_recent_activity` | This cookie is used to prevent showing the security interstitial to users that have visited the app recently. | One hour | |
| 22 | 22 | | GitHub | `__Host-gist_user_session_same_site` | This cookie is set to ensure that browsers that support SameSite cookies can check to see if a request originates from GitHub. | Two weeks | |
| 23 | 23 | | GitHub | `__Host-user_session_same_site` | This cookie is set to ensure that browsers that support SameSite cookies can check to see if a request originates from GitHub. | Two weeks | |
| 24 | 24 | | GitHub | `logged_in` | This cookie is used to signal to us that the user is already logged in. | One year | |
| 25 | 25 | | GitHub | `marketplace_repository_ids` | This cookie is used for the marketplace installation flow. | One hour | |
| 26 | 26 | | GitHub | `marketplace_suggested_target_id` | This cookie is used for the marketplace installation flow. | One hour | |
| 27 | | GitHub | `notifications_web_disabled` | This cookie caches whether web notifications are disabled, so the global navigation notifications indicator can be rendered without an additional lookup. | One month | | |
| 27 | 28 | | GitHub | `_octo` | This cookie is used for session management including caching of dynamic content, conditional feature access, support request metadata, and first party analytics. | One year | |
| 28 | 29 | | GitHub | `org_transform_notice` | This cookie is used to provide notice during organization transforms. | One hour | |
| 29 | 30 | | GitHub | `private_mode_user_session` | This cookie is used for Enterprise authentication requests. | Two weeks | |
| 30 | 31 | | GitHub | `saml_csrf_token` | This cookie is set by SAML auth path method to associate a token with the client. | Until user closes browser or completes authentication request | |
| 31 | 32 | | GitHub | `saml_csrf_token_legacy` | This cookie is set by SAML auth path method to associate a token with the client. | Until user closes browser or completes authentication request | |
| 32 | 33 | | GitHub | `saml_return_to` | This cookie is set by the SAML auth path method to maintain state during the SAML authentication loop. | Until user closes browser or completes authentication request | |