How Central Uses Cookies

Prev Next

Municipal Websites Central does not include a built-in cookie consent banner. Instead, it relies on browser-level cookie controls. Visitors can allow, block, or delete cookies through their own browser settings. Municipal Websites Central honors these choices. Some organizations want more control over cookie consent, such as a banner where visitors can opt in or opt out. If this is something you want, see Need More Control.

Your site's published Privacy Policy includes general cookie language. You can view it at /site/privacy on your site, and edit it through Site Properties. This article goes into more technical detail for support purposes and for administrators who want to understand exactly what is being set and why.


How Visitors Can Control Cookies

Cookie behavior is controlled at the browser level, not through a Municipal Websites Central setting. Visitors can typically:

  • Allow or block cookies from specific sites

  • Delete existing cookies

  • Set their browser to ask before accepting cookies

  • Browse in a private/incognito window, which limits persistent cookies

Instructions vary by browser, such as Chrome, Firefox, Safari, or Edge. We recommend directing visitors to their browser's own help documentation for exact steps.


Cookies Municipal Websites Central Sets

Session Cookies

Cookie

Purpose

Notes

.AspNet.Cookies

Authentication

Stores an encrypted authentication identifier. This can only be decoded on the server, not in the browser. No session identifiers are ever passed through the URL. The cookie is flagged HTTPOnly and Secure.

ASP.NET_SessionId

Session management

Flagged HttpOnly and Secure.

Secure flags are enforced because Municipal Websites Central applies SSL site-wide.

If a visitor selects Remember Me at login, Municipal Websites Central stores their username in a persistent cookie. This pre-fills the username on future visits.

Persistent Preference Cookies

Municipal Websites Central sets a small number of persistent cookies. These cookies remember site preferences, such as whether editing mode is turned on or the last content category a visitor viewed. They are not sensitive and do not carry personal or session data.

Cookies with Attribute Constraints

Most Municipal Websites Central cookies are HttpOnly and Secure. A few can't carry that full combination because of how they function:

Cookie

Purpose

Note

CP_TrackBrowserCentralLegacy

Legacy browser compatibility messaging

Requires JavaScript read access, so it cannot be HttpOnly. Secure is applied when the site enforces SSL.

viewportWidth

Responsive layout and resize logic

Same JavaScript-access constraint as above.

__RequestVerificationToken

ASP.NET anti-forgery / CSRF (Cookies with Attribute Constraints) protection

HttpOnly by default. Secure is applied when the site has SSL enforcement enabled.

Other Functional Cookies

You may also see isLoggedIn, ResponsiveGhost, and CP_IsMobile on a Municipal Websites Central site. These support login state and mobile/responsive rendering, and don't contain sensitive data.

Cookies Set by Page-Level Features

Some page-level features, such as polls, can set extra cookies depending on how they are set up. The list above covers the cookies most commonly found across scans. It may not include every cookie for every feature combination. If you find a cookie that is not listed here, contact support to submit a support ticket with the cookie name and where you found it. We will follow up with an answer.


Third-Party Cookies

Municipal Websites Central does not set tracking cookies itself. However, third-party services you choose to embed on your site can set their own cookies. Examples include Google Analytics, Google Translate, Microsoft Application Insights, reCAPTCHA, and chatbot widgets. These cookies are outside Central's direct control. Each provider's own privacy policy, not Municipal Websites Central's, governs visitors' cookie preferences for those services.


Need More Control?

Some organizations want a configurable, visitor-facing consent experience. This can help support GDPR or CCPA compliance, categorize cookies for visitors, or keep a consent log. For this, you can use the Consent Manager available through our AWG (Acquia Web Governance) partnership. It lets you categorize cookies by compliance standard, customize a consent banner to match your brand, and log visitor consent for documentation. Contact your account team for more information.