Browser Compatibility & Cookies
About Browser Compatibility & Cookies
This page details Qualtrics’ browser compatibility. It also lists all the cookies Qualtrics places on your browser when you are taking a survey; these cookies are generally meant to help keep track of survey sessions so that they aren’t repeated, or to maintain the session.
Browser Compatibility
Qualtrics is committed to providing secure, high quality products that are functional and consistent across the most popular modern web browsers. Qualtrics officially supports all of its web-based products in OEM (Original Equipment Manufacturer) supported versions of the following browsers:
- Apple Safari
- Google Chrome
- Microsoft Edge (Chromium Version)
- Mozilla Firefox
Versions of these browsers no longer supported by their maker may not function as intended and may expose the user to inherent security vulnerabilities. Qualtrics recommends that users always use the most up-to-date version of their browser.
Survey Session Management Cookies
The cookies in this section are used to manage survey sessions (i.e., when the survey is open for a specific respondent).
Session Cookie
- Description: Appears when you start a session with “Allow respondents to finish later” enabled.
- Cookie Name: `<hash of the session ID and query parameters>`
- Cookie Value: `<session ID>~<internal Qualtrics ID>`
- Expires: 6 months, or when the session is completed
SFA cookie
- Description: Allows a user to access a previously uploaded file when resuming a session.
- Cookie Name: `SFA`
- Cookie Value: `<session ID>`
- Expires: 6 months
Survey Authentication Cookies
The cookies in this section are used for survey authentication (i.e., making sure the right person is taking the survey).
Single reload cookie
- Description: Temporary cookie used to allow survey takers to resume their session following an SSO authenticator.
- Cookie Name: `<hash of the session ID and query parameters>-singleReload`
- Cookie Value: `<session ID>~<internal Qualtrics ID>`
- Expires: 5 minutes, or when respondent is redirected back to the survey from the SSO authenticator.
Reauth cookie
- Description: Temporary cookie after reauthenticating in a survey with “Require respondents to authenticate again if they resume their session later.”
- Cookie Name: `<Survey ID><SessionID>-reauth`
- Cookie Value: `<internal Qualtrics ID>`
- Expires: 5 minutes
Auth session cookie
- Description: Keeps track of a user’s logged in status after passing an authenticator with the “Require respondents to authenticate again if they resume their session later” authenticator setting enabled.
- Cookie Name: `reauth-<hash of session ID and authenticator flow ID>`
- Cookie Value: `<signed login token>`
- Expires: 1 hour
Submitting Survey Sessions Cookie
The cookie in this section prevents survey takers from taking the same survey multiple times.
QST Cookie
- Description: This cookie enforces the “Prevent multiple submissions” setting in survey options. It only appears once a survey session has been submitted.
- Cookie Name: QST
- Cookie Value: `<SurveyID>`
- Expires: 6 months
Survey Preview Cookies
The cookies in this section are used to manage survey previews.
XSRF Token
- Description: This is a temporary cookie used for security while survey taking. It is only stored as long as the browser is open.
- Cookie Name: XSRF-TOKEN
- Cookie Type: session
PreviewDC Cookie
- Description: Used to keep track of state while interacting with a preview link.
- Cookie Name: previewDC
- Cookie Value: <internal Qualtrics ID>
- Expires: 30 days
Bot Manager Cookies
The cookies in this section are used to help distinguish between real website traffic from bot traffic. These cookies come from the Akamai’s Bot Manager solution being used inside the Qualtrics platform.
ak_bmsc
This cookie is related to our bot detection and prevention mechanism provided by our web application firewall provider. This cookie is used to track the progress of the session going through the standard detection workflow. When present, it is also used as the identifier instead of the IP address for bot rate control rules.
- Cookie name: ak_bmsc
- Expires: 2 hours
- Size: approximately 300 bytes
- HttpOnly set by default: true
- Secure flag enabled by default: false
- SameSite set by default: false
Website / App Insights Browser Cookies
Website / App Insights stores certain data inside cookies. This includes the Site History cookie, Prevent Repeated Display cookie, a cookie that tells us that we have a Pop Under, a cookie that stores history data if localStorage is disabled, and a cookie that tracks user events.
For a full description of all relevant cookies, see this support page.