What is the _gat cookie?
Used by Google Analytics to throttle the request rate and limit data collection on high-traffic sites.
Table of Contents
About the _gat cookie
| Vendor | |
|---|---|
| Category Category The functional category of the technology, such as Web Analytics or Social Media. Learn more | Heatmap & Recording |
| Consent Category Consent Category The consent category this cookie most commonly falls under across sites we scan, normalized into four standard categories. Learn more | Performance & Analytics |
| Prevalence | Very Common |
| Popularity Popularity Popularity is calculated from our dataset of 4.5B+ cookies analyzed across hundreds of millions of web pages. Learn more | Found on 21.3% of scanned pages |
| Expiration Type | Timestamp |
| Party Type Party Type Whether the cookie is first-party or third-party. Learn more | 1st-Party |
| Risk Level Risk Level Rates how sensitive the data stored by this cookie is (High, Medium, or Low) based on data classification and distribution. Learn more | Low |
| Vendor Privacy Policy | https://policies.google.com/privacy |
| Vendor Website | https://www.google.com/ |
What is the purpose of the _gat cookie?
The _gat cookie (along with its dynamically named variants such as _gat_UA-XXXXX) is a first-party technology set by Google Universal Analytics. Its primary technical purpose is to limit the rate of data requests sent to Google's servers. By throttling these requests, it helps manage data collection volume on high-traffic websites and preserves system stability. Unlike other Google Analytics cookies, this specific cookie does not store any persistent unique user identifiers. When deployed via Google Tag Manager, it may alternatively be named _dc_gtm_<property-id>.
What are the Privacy Risks of the _gat cookie?
Risk Level: Low
The _gat cookie is classified as Low risk because, unlike other Google Analytics tracking cookies (such as _ga or _gid), it does not store pseudonymous identifiers or behavioral user data. Its sole purpose is strictly for technical site functionality: throttling the request rate to limit the amount of traffic transmitted to Google's analytics servers.
How to Remove the _gat cookie from a Website
To remove the _gat cookie, website administrators must completely remove the Google Analytics tracking script (such as analytics.js or the corresponding Google Tag Manager tracking configuration) from the website's source code. Because this cookie is an integrated component of how Google Universal Analytics manages its network requests, it cannot be disabled independently without removing the entire analytics service from the page.
This definition was last reviewed on August 19, 2026. ObservePoint regularly reviews these definitions to ensure our customers have the most up to date information about the cookies on their websites.