<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1198476139004771&amp;ev=PageView&amp;noscript=1">

Sunset of the hs-membership-csrf cookie

What is it?

This cookie protects logins to HubSpot-gated content, including private pages, customer portals, and membership sites. On August 21, 2026, HubSpot sunset 'hs-membership-csrf' and replaced it with '__Host-hs-membership-csrf' to strengthen login security.

 

Why does it matter?

HubSpot no longer issues the old cookie. If your consent platform only allows the old name, it may block the new cookie when visitors decline non-essential cookies. Those visitors cannot log in and see "An unexpected error occurred."

 

How does it work?

Action required: Add '__Host-hs-membership-csrf' to your consent platform's essential-cookie allowlist.

See Cookies set in your visitor's browser by HubSpot for more information.

 

Who gets it?

Content Hub Enterprise, Service Hub Professional, Service Hub Enterprise, Content Hub Professional

Topics: Service Hub Enterprise, Service Hub Professional, Content Hub Enterprise, Content Hub Professional

Related articles


New Guidelines UI for Customer Agent
29 Sep 2026

[Opt-in] New Help Desk Composer Experience
29 Sep 2026

Ready to maximize your business growth with our HubSpot-accredited services?

Contact us today to learn how we can help you succeed.