The _fbp and _fbc cookies are two first-party cookies set on your website by the Meta Pixel. The _fbp cookie gives each browser an identifier so Meta can connect its visits and actions, and the _fbc cookie stores the click ID when someone arrives from a Facebook or Instagram link, such as an ad.
How _fbp and _fbc work
_fbp is created the first time the pixel loads in a browser, provided first-party cookies are enabled in the pixel settings. Its value looks like fb.1.1727000000000.1234567890: a version prefix, the time it was created and a random number. It typically lasts 90 days and is refreshed on later visits.
_fbc is created only when someone lands on your site from a link containing an fbclid parameter, which Meta adds to links clicked on Facebook and Instagram, including ads. The cookie stores that click ID with a timestamp, in the form fb.1.timestamp.fbclid, so later events, such as a purchase three pages on, can be tied back to the ad click.
Both values matter even more when you use the Conversions API. Server events sent directly to Meta do not carry browser cookies automatically, so your server reads _fbp and _fbc and passes them as the fbp and fbc parameters. They are among the strongest signals Meta uses to match a server event to a person, and they feed into Event Match Quality.
Because these cookies are set by JavaScript, browsers can shorten their life. Safari’s tracking prevention can cut cookies set this way to as little as seven days, and shorter still in some cases.
Meta also lets you switch first-party cookies off in the pixel’s settings in Events Manager. If they are off, neither cookie is written and attribution has to rely on weaker signals, so check that setting before troubleshooting anything else.
Why it matters
Without _fbp and _fbc, Meta has a harder time recognising who converted, so fewer purchases and leads are attributed to your ads and the delivery system has less to learn from. A Leeds clothing shop running server-side tracking that forgets to pass these two values would see weaker match quality than the setup should achieve.
For UK visitors there is a clear legal line. These are marketing cookies, not strictly necessary ones, so under PECR they must not be set until the visitor has agreed. That means the pixel, and any server-side code that reads or creates these values, must respect your consent banner. The analytics exception in the Data (Use and Access) Act 2025 does not extend to advertising cookies of this kind.
Common mistakes
- Loading the Meta Pixel before consent, so _fbp is set for every UK visitor.
- Not passing fbp and fbc with Conversions API events.
- Changing the case of the fbclid value when building _fbc on the server. The value is case-sensitive.
- Creating _fbc server-side for visitors who declined marketing cookies.
- Stripping URL parameters on redirects, so the fbclid never reaches the landing page.
How to act on it
Open your site in a private window, decline cookies and check in your browser’s developer tools that neither cookie appears. Then accept, click through from a test ad link with an fbclid, and confirm both are set.
If you use the Conversions API, check in Events Manager that server events include fbp and fbc, and look at the match quality score. Make sure redirects keep query parameters.
Checking consent behaviour and server-side parameters together is a standard part of the tracking setup I do in Facebook and Instagram ads management.
