Skip to main content
Version: 8.1

Creatio Platform Cookies

Creatio may use the following types of cookies and similar technologies to operate and improve Creatio services:

  • Essential / strictly necessary cookies required for the operation of the Creatio services. For example, they include cookies that let you log in to secure areas. Strictly necessary cookies facilitate the operation of our websites. Without the use of these cookies, portions of our websites will not function properly.
  • Functional cookies that remember choices you make and recognize you when you return. This enables us to personalize our content, greet you by name and remember your preferences (for example, your choice of language or region) or allow the pre-population of certain resource request forms, making it easier for you to access Creatio content.

See more details on cookies and how Creatio processes cookie data in Creatio Privacy Policy.

his table describes the cookies used by Creatio platform:

Cookie Name

Duration

Cookie Type

Description

ASPXAUTH

Session cookie

Strictly necessary

Stores information about the authorized state of the user and to provide access to protected resources only to authorized users.

May store identifiable data.

BPMLOADER

Session cookie

Strictly necessary

Required for the website to work properly.

Stores a unique ID of anonymous sessions.

Does not store identifiable data.

BPMSESSIONID

Session cookie

Strictly necessary

Required for the website to work properly.

Stores a unique ID of the session.

May store identifiable data.

BPMCSRF

Session cookie

Strictly necessary

Protects against cross-site requests (CSRF).

Stores a unique token that is checked by the server to confirm the legitimacy of requests, thereby preventing possible CSRF attacks.

Does not store identifiable data.

UserName

Cookie exists <number-of-days-to-remember-cookie> set in system setting UserNameExpireDays.

Disabled by default.

Functional cookie (Optional)

Stores a user ID for easier log in to the platform.

Set after successful user authorization and can be activated and deactivated on the customer’s level by setting the UserNameExpireDays system setting.

To activate, set the system setting “User name expiration term (days)” (“UserNameExpireDays” code) to <number-of-days-to-remember-cookie>.

To deactivate, set the system setting “User name expiration term (days)” (“UserNameExpireDays” code) to 0.

May store identifiable data.

UserType

Session cookie

Strictly necessary

Stores user type. Set after successful user authorization.

Does not store identifiable data.

SsoSessionId

Session cookie

Strictly necessary (for Single Sign-On functionality)

Stores session ID of the user authenticated via Single Sign-On mechanism.

May store identifiable data

Creatio can run without the use of functional cookies, but doing so can reduce functionality. The impact on functionality depends on the purpose of the blocked cookie.

Creatio currently does not provide functionality for cookie consent management.

See also

Recommended information security settings

Set up content security policy

Set up secure storage of sensitive data using Vault