Privacy
First-party cookie
Also called 1P cookie.
First-party cookie is a cookie set on the site's own registrable domain, the one the visitor sees in the address bar. Logins, carts, and many analytics IDs use them.
How it is measured
Open the storage panel and read the Domain column. If it matches the page's domain, it is first party. Then check how it was written: a Set-Cookie header from your server, or document.cookie from a script.
That second answer sets its lifetime in Safari. Script-written cookies are capped at seven days, while server-set cookies are treated more kindly unless the host is flagged as a tracker.
Worked example
A garden-centre site loads an analytics script that writes a two-year cookie on its own domain. A Chrome visitor keeps the ID for months. A Safari visitor who returns on day nine finds the cookie gone and is counted as new.
The monthly report shows new-visitor share at 71 percent for iPhone traffic and 52 percent for Android, with no change in the real audience.
How it differs
A first-party cookie belongs to the domain being visited. A third-party cookie belongs to another host embedded in the page. The first excludes cross-site reach by design; the second excludes the site owner's control over it.
Common errors
Assuming first party means no consent is needed. Believing the label exempts it from Safari limits. Hiding a vendor behind a CNAME and calling it yours. Setting a two-year expiry and trusting it to last. Skipping Secure and SameSite on a login cookie.
In practice
List your cookies by domain and by who wrote them. Keep those needed to run the site, such as login and cart, and challenge the rest. For anything analytical, ask whether you need a stored ID at all.