Mediaposte Martech | HubSpot Feature Updates

Sunset of the hs-membership-csrf cookie

Written by Catalin Vlad | Sep 29, 2026, 1:47:01 PM

What is it?

This cookie protects logins to HubSpot-gated content, including private pages, customer portals, and membership sites. On August 21, 2026, HubSpot sunset 'hs-membership-csrf' and replaced it with '__Host-hs-membership-csrf' to strengthen login security.

 

Why does it matter?

HubSpot no longer issues the old cookie. If your consent platform only allows the old name, it may block the new cookie when visitors decline non-essential cookies. Those visitors cannot log in and see "An unexpected error occurred."

 

How does it work?

Action required: Add '__Host-hs-membership-csrf' to your consent platform's essential-cookie allowlist.

See Cookies set in your visitor's browser by HubSpot for more information.

 

Who gets it?

Content Hub Enterprise, Service Hub Professional, Service Hub Enterprise, Content Hub Professional