You will learn

Learn how to set up First-Party ID to improve your ability to identify returning visitors. First-Party ID uses a server-side cookie to extend identification, helping you recognize more returning shoppers, attribute more onsite events, and power more targeted marketing automation

If you choose to turn on First Party ID, it is strongly suggested that you re-issue your cookie notices to your customers, and that you review your Terms of Service and/or Privacy Notice to ensure that your customers are notified of re-identification processes. The Klaviyo cookie will expire, but First-Party ID provides re-identifcation through a server side cookie feature that allows you to refresh the Klaviyo cookie directly from your own domain.

Please read more about Privacy Notice, Cookie Notice, and Consent in the Understanding cookies in Klaviyo article.

How does First-Party ID work?

Klaviyo's standard tracking sets a cookie called __kla_id in the visitor's browser using JavaScript (read more here). On browsers like Safari and Firefox, privacy protections cap how long that cookie persists. Once it expires, Klaviyo can no longer recognize the visitor as a known profile until another identification event.

First-Party ID addresses this by running a Cloudflare worker on a subdomain of your own domain. This worker sets a long-lived, server-set cookie called __kle_id. When your existing __kla_id expires, Klaviyo uses __kle_id to refresh it, re-identifying the visitor and attributing their active onsite session to the correct known profile. If the worker is ever unavailable, Klaviyo falls back gracefully to standard __kla_id behavior (Klaviyo Javascript), so no data is lost.

  • Note: First-Party ID does not identify net new visitors. A shopper must already have a Klaviyo profile — created through a signup, tracked email click, or other identification event — before First-Party ID can re-identify them on a return visit.

Cookie Lifetime Duration

When a visitor is identified, the Klaviyo cookie (__kla_id) is set to last up to 2 years, but its duration will vary depending on each browser’s cookie lifetime policies - which is informed by how the cookie is set in the browser. __kla_id is typically set using the Klaviyo Javascript, which places the cookie client side. If Extended ID or First Party ID are enabled, the Klaviyo cookie is set client side and server side respectively. Learn more about how to enable these Klaviyo features to help re-identify users. Learn how to set up Extended ID.

The standard __kla_id cookie lifespan — how long it lasts before First-Party ID needs to refresh it — varies by browser. More detailed information can be found on this CookieStatus.

  • Cookie lifetime varies by browser and depends on whether the cookie is set client-side by JavaScript or server-side. The table below shows both.

Browser

Standard __kla_id lifespan (placed client side – JS + Extended ID)

With First-Party ID (server-set)

Safari

24 hours (URL contains query parameters or fragments + if Klaviyo is a known tracker); otherwise 7 days

Up to 7 days

Brave

If Brave's 'Shields Down' mode is enabled, 7 days; otherwise, the Klaviyo cookie is blocked by Brave

If Brave's 'Shields Down' mode is enabled, 7 days; otherwise, the Klaviyo cookie is blocked by Brave

Firefox

45 days lifetime limit; however, Firefox purges via daily tracker-classification checks

45 days lifetime limit; however, Firefox purges via daily tracker-classification checks

Chrome

400 days

Up to 400 days

Edge

Up to two years (Klaviyo's own setting — not an Edge restriction)

Up to two years (Klaviyo's own setting — not an Edge restriction)

Safari's 24-hour restriction applies specifically when the cookie is placed client side, the URL contains query parameters or fragments, and if Klaviyo is considered a known tracker by Safari. Under normal conditions, Safari's limit for JS-set first-party cookies is 7 days.

Enabling First-Party ID

First-Party ID requires a dedicated subdomain on your domain that points to Klaviyo's Cloudflare account. Klaviyo provides the DNS records needed.

  • Click the account menu in the lower left of your Klaviyo account.
  • Select Settings from the menu.
  • Navigate to the Data Tab
  • In the First-Party ID section, click “Configure”.
  • Confirm that the pre-filled domain is correct. If not, enter the root domain (i.e. example.com) of your storefront and click next.
  • To set up your subdomain, you can choose to use Entri to provide a few details and have it configure the subdomain automatically for you. Alternatively, you may choose to set up the subdomain manually via your DNS provider’s settings.
  • If selecting Entri
    • Click Connect with Entri and Continue
  • Entri will automatically detect your domain’s DNS provider and ask for a few details, including login details. Follow the on-screen instructions and Entri will automatically add the subdomain to your DNS records.
  • If selecting manual
    • Copy paste the CNAME record displayed on your screen into your DNS provider.
  • Click Verify
  • Setup is now complete, and the Klaviyo system will take up to 48 hours to verify that the subdomain is beginning to receive traffic correctly. You will receive an email when the subdomain is done verifying and First-party ID is running!

Each domain can only be connected to one Klaviyo account at a time — it can't be reused across other portfolio accounts, even if they share the same URL. Klaviyo will send an email when your subdomain status changes (e.g., from Pending DNS to Active, or if an error is detected). Once Active, Klaviyo's JavaScript will automatically begin calling the worker on your subdomain.

Subdomain Status States

In App Status

Email Status

What it means

Verifying

N/A

Klaviyo has created the subdomain configuration and is waiting for your DNS records to be added and detected.

Active

Once active, you will receive an email informing you that First-Party ID is set up.

Setup is complete. First-Party ID is live and Klaviyo.js is calling your worker on each page load.

Failed

If something fails, you will receive an email alerting you.

This can occur for a few reasons including the inability to connect to your subdomain. The email will contain instructions on how to resolve the issue.

Inactive

An email will be sent alerting you to check your DNS.

This may occur if you were previously Active, but we are no longer receiving traffic from your domain. Please check to make sure it is configured correctly by following the steps above for checking your DNS Provider, attempting to connect to your subdomain, or try deactivating and reactivating First Party ID.

My subdomain status shows failed

An Error status means Cloudflare detected a problem with your subdomain configuration. Common causes:

  • CNAME record is missing or pointing to the wrong target.
  • DNS record was added but did not fully propagate (can take up to 48 hours in rare cases).
  • The CNAME target provided by Klaviyo was entered incorrectly.

To resolve: Depending on the issue, you will receive an email with instructions pertaining to that issue. Generally you will need to verify your DNS records match exactly what was displayed in the setup flow, then click Re-configure in the First-Party ID settings. If the issue persists, contact Klaviyo support.

Tip: If the setup is stuck in Pending DNS for more than 60 minutes, verify that your CNAME record has propagated using a tool like dnschecker.org. DNS propagation times vary by provider.


Disabling First-Party ID

To turn off First-Party ID:

  1. Click the account menu in the lower left of your Klaviyo account.
  2. Select Settings from the menu.
  3. Navigate to the Data tab.
  4. In the First-Party ID section, click the deactivate button.

Disabling First-Party ID immediately stops the worker from refreshing __kla_id. Your account reverts to Klaviyo's standard JavaScript cookie tracking. The subdomain configuration is preserved if you re-enable later.

Measuring the Impact of First-Party ID

To view the impact of First-Party ID on your brand's ability to identify visitors, you can leverage the Active on Site event.

  1. Navigate to Analytics —> Metrics —> Active on Site.
  2. Add the filter By —> ssc_refresh.


This demonstrates the number of additional active on site events that were captured due to First Party ID. First Party ID events have a value of 1.0 (i.e., true) while events captured with Klaviyo's standard cookie tracking or Extended ID have a value of 0.0 (i.e., false).

First-Party ID is Active but I'm not seeing the ssc_refresh property in Active on Site

The ssc_refresh flag is only set on events that were captured after a successful worker rehydration. If no visitors have returned to your site after their __kla_id expired, no ssc_refresh events have occurred yet.



Understanding First-Party ID Attribution

Klaviyo tracks "attributed" onsite events — sessions where First-Party ID successfully re-identified a returning shopper after their __kla_id expired. An attributed event means:

  • The visitor previously had a Klaviyo profile (created via signup, email click, form submit, etc.).
  • Their __kla_id cookie expired between visits.
  • They returned to your site and the worker returned their stored identity from __kle_id.
  • Klaviyo restored __kla_id and tagged the session with ssc_refresh = 1.0.
    • The ssc_refresh flag is set at the exact point when the worker successfully rehydrates __kla_id. That's when attribution is logged.
  • All subsequent onsite events in that session (page views, added to cart, etc.) are attributed to the known profile.

A visitor who was identified yesterday - not by First Party ID - and returns today (while their __kla_id is still valid) will not show a First-Party ID attribution event — the worker was not needed for re-identification on that visit.


Common Questions about Setting Up First-Party ID

Answers to what customers most often ask while getting First-Party ID running:

  1. Does First Party ID use fingerprinting, and can it re-identify across multiple devices?
    1. First-Party ID does not use fingerprinting, probabilistic identifiers, IP addresses, device data, click IDs, or user agent strings.
    2. Re-identification across multiple devices or browsers is not supported.
  2. Does First party ID integrate with CAPIs?
    1. First-Party ID does not integrate with conversion APIs (CAPIs).
  3. Can you use more than one domain on a Klaviyo account with First Party ID?
    1. Each domain can only be assigned to First-Party ID on one Klaviyo account. If the same URL is shared across multiple portfolio accounts (for example, a US and CA storefront on the same domain), you can only enable First-Party ID on one of them.
  4. How long does DNS setup take?
    1. Usually just a few minutes once your CNAME record is added, but it can take up to 48 hours depending on your DNS provider. If you're stuck in Pending DNS for more than 60 minutes, confirm propagation with a tool like dnschecker.org.
  5. Can I use the same domain on more than one Klaviyo account?
    1. No. A domain can only be assigned to First-Party ID on a single Klaviyo account, and can't be reused across other portfolio accounts — even if two accounts share the same URL (for example, a US and CA storefront on the same domain).
  6. Do I need to update my privacy policy before enabling First-Party ID?
    1. If you choose to turn on First Party ID, it is strongly suggested that you re-issue your cookie notices to your customers, and that you review your Terms of Service and/or privacy notice to ensure that your customers are notified of re-identification processes. The Klaviyo cookie will expire, but First-Party ID provides re-identifcation through a server side cookie feature that allows you to refresh the Klaviyo cookie directly from your own domain.
    2. Please read more about Privacy Notice,Cookie Notice, and Consent in the Understanding cookies in Klaviyo article.
  7. Do I still need Extended ID if I set up First-Party ID?
    1. The two work together rather than replacing each other. First-Party ID takes priority when both are enabled, and Extended ID continues to catch visitors First-Party ID hasn't reached yet.
  8. Will this break my tracking if something goes wrong during setup?
    1. No. If the worker is ever unreachable, Klaviyo automatically falls back to standard __kla_id behavior. No data is lost.
  9. How soon after enabling will I see First-Party ID attributed events?
    1. It depends on the browser mix of your traffic. First-Party ID can only refresh __kla_id once an existing cookie expires and the visitor returns, so check back in 3 weeks for early signal, and then again in about 2 months for more established impact.
  10. I just enabled First-Party ID. Why am I not seeing any attributed events yet?
    1. This is expected. First-Party ID can only refresh __kla_id once a visitor's existing __kla_id has expired and they return to your site. The timeline depends on the browser. Check back in 3 weeks for early signal, particularly from Safari traffic. Attribution builds gradually as existing cookies expire and shoppers return.
  11. I have Extended ID enabled, and I turned on First-Party ID. Why are First-Party ID attributed events lower than Extended ID attributed events?
    1. This is expected, especially in the early weeks. Extended ID may have recently refreshed __kla_id for many shoppers, meaning those cookies still have time remaining on their TTL before First-Party ID can take over.
    2. The pipeline to get a First-Party ID attribution requires three things in sequence: identification event → __kla_id expiry → return visit. We're still waiting on those expiries to roll through.
    3. Over time, attribution should shift: Extended ID attributed events will trend down as First-Party ID grows. The key signal to watch: First-Party ID attributed events should grow by more than Extended ID attributed events decline — that confirms net new identification, not just displacement.

Additional resources

  • How to set up extended ID cookie tracking

    Learn how to set up extended ID to compliantly capture and track subscriber interactions with your brand for longer. Extended ID is a first-party identity graph feature that allows you to track and hold cookies for up to 1 year. Thus allowing you to identify these interactions and behaviors longer to target, segment, and automate marketing messages.

  • Understanding cookies in Klaviyo

    Learn more about how Klaviyo uses cookies as a part of our web tracking to gather information and help improve conversion rates and email performance. This article explains the specific cookie we use and its purposes so that you understand how customers are tracked. This information helps you understand how Klaviyo gathers data, and how this may impact customer privacy and compliance laws.

Was this article helpful?
Use this form only for article feedback. Learn how to contact support.

Explore more from Klaviyo

Community
Connect with peers, partners, and Klaviyo experts to find inspiration, share insights, and get answers to all of your questions.
Partners
Hire a Klaviyo-certified expert to help you with a specific task, or for ongoing marketing management.
Support

Access support through your account.

Email support (free trial and paid accounts) Available 24/7

Chat/virtual assistance
Availability varies by location and plan type