What is the YSC cookie?
This cookie is set by YouTube on pages with embedded videos to help ensure that requests made within a browsing session originate from the user rather than from other (potentially malicious) sites.
Table of Contents
About the YSC cookie
| Vendor | |
|---|---|
| Cookie Domain | youtube.com |
| Category Category The functional category of the technology, such as Web Analytics or Social Media. Learn more | Data Management (DMP) |
| Consent Category Consent Category The consent category this cookie most commonly falls under across sites we scan, normalized into four standard categories. Learn more | Strictly Necessary |
| Prevalence | Very Common |
| Popularity Popularity Popularity is calculated from our dataset of 4.5B+ cookies analyzed across hundreds of millions of web pages. Learn more | Found on 28.3% of scanned pages |
| Expiration Type | Session |
| Party Type Party Type Whether the cookie is first-party or third-party. Learn more | 3rd-Party |
| Risk Level Risk Level Rates how sensitive the data stored by this cookie is (High, Medium, or Low) based on data classification and distribution. Learn more | Low |
| Vendor Privacy Policy | https://policies.google.com/privacy |
| Vendor Website | https://www.google.com |
What is the purpose of the YSC cookie?
The YSC cookie is a third-party tracking and security identifier set by Google (via the YouTube domain) on websites that embed YouTube video players. According to Google's documentation, its primary technical purpose is to ensure that requests within a browsing session are genuinely made by the user rather than by unauthorized cross-site requests, thereby preventing malicious sites from executing actions on the user's behalf.
Additionally, privacy databases and technical analyses observe that YSC functions to store and track a user's interaction with the embedded YouTube video player. It registers a unique session identifier that enables YouTube to maintain statistics on video views and correlate a user's actions during that specific browsing session. Since the cookie is set from the youtube.com domain, it operates as a third-party tracking mechanism on the host website.
What are the Privacy Risks of the YSC cookie?
Risk Level: Low
The YSC cookie is classified as Low risk because Google documents it as a session-based security/anti-abuse mechanism designed to ensure that in-session requests are genuinely made by the user rather than by other sites. It does not persist across sessions to track long-term user behavior, nor is it documented by Google as an advertising or profiling identifier. While it is set by a third-party domain (youtube.com) and some cookie databases classify it as targeting/advertising, its documented purpose is limited to securing the video player's interactions during the current browsing session, and it expires when the browser closes.
How to Remove the YSC cookie from a Website
To remove the YSC cookie, website administrators must modify how YouTube videos are embedded on the site. Since the cookie is automatically set by the standard YouTube iframe or API, removing the YouTube embed entirely will stop the cookie from being set. If video content must remain, administrators can switch the embed URL from the standard youtube.com domain to YouTube's privacy-enhanced domain (youtube-nocookie.com). The privacy-enhanced mode prevents YouTube from setting tracking cookies, including YSC, until the user actively clicks to play the video. Alternatively, administrators can replace the iframe with a static thumbnail image that only loads the video player when clicked.
This definition was last reviewed on August 19, 2026. ObservePoint regularly reviews these definitions to ensure our customers have the most up to date information about the cookies on their websites.