Sidekick Strategies
Events
Contact UsSchedule a Strategy Call
HubSpot updates comic hero background

HubSpot Updates

Sunset of the hs-membership-csrf Cookie

September 22, 2026

What This Update Actually Is

HubSpot sunsetted the hs-membership-csrf cookie and replaced it with __Host-hs-membership-csrf. The change went live on August 21, 2026.

This cookie is a CSRF (Cross-Site Request Forgery) token. It's what keeps login sessions secure on HubSpot-gated content: private pages, customer portals, and membership sites. It's classified as an essential cookie, meaning it has to work even when a visitor declines non-essential tracking.

The __Host- prefix is the meaningful change. It's a browser-level security enforcement that locks the cookie to the exact host (no subdomains, no insecure connections). HubSpot isn't just renaming a cookie; they're adopting a stronger security standard.

Why HubSpot Shipped This

The original cookie name had no host-binding enforcement. A bad actor could, under certain conditions, set or intercept that cookie across related domains. The __Host- prefix closes that gap at the browser level, not just at the application level.

For the humans running portals with customer-facing login experiences, this is a meaningful upgrade. Membership sites and customer portals handle real credentials. Stronger session security protects those humans and the companies serving them.

The internal frustration this update speaks to is real: consent platforms (OneTrust, Cookiebot, CookieYes, and similar tools) require exact cookie names to allow them through when a visitor opts out of non-essential tracking. A name change that isn't reflected in your allowlist silently breaks logins. Visitors don't see a permissions screen. They see: "An unexpected error occurred." That's a terrible experience, and it erodes trust fast.

How to Use It Step by Step

  1. Log in to your consent management platform (OneTrust, Cookiebot, CookieYes, or whichever tool you use).
  2. Navigate to your cookie list or cookie allowlist settings.
  3. Find any entry for hs-membership-csrf in the essential or strictly necessary category.
  4. Add __Host-hs-membership-csrf as a new essential cookie entry. Keep the old name if your platform supports it, since some older browsers may still send it briefly during transitions.
  5. Publish or save the updated cookie configuration.
  6. Test login on your private pages or customer portal while in incognito mode with cookies set to decline non-essential. Confirm the login completes without error.

That's it. This is a one-time configuration update, not an ongoing change. But it has to happen. HubSpot stopped issuing the old cookie on August 21, 2026.

What It Touches in Your HubSpot Strategy

This update is narrow in scope but wide in consequence if you ignore it. Here's where it shows up across your portal.

Private Pages and Membership Sites (Content Hub). Any page gated behind HubSpot membership login relies on this cookie. If a visitor declines non-essential cookies and your allowlist doesn't include the new name, their login attempt fails with a generic error. They don't know why. They just leave.

Customer Portal (Service Hub). The customer portal uses the same cookie-based login mechanism. Humans accessing their support tickets or account details will hit the same wall. That's a service experience problem, not just a tech problem.

Key Takeaway

The cookie is classified as essential, meaning it should always be allowed. But consent platforms only know what you tell them. If your allowlist is outdated, the platform may block the cookie anyway. You need to update the name manually.

Consent Platform Configuration. This update lives at the intersection of HubSpot and your consent management stack. If you've never audited your consent platform's cookie list against HubSpot's actual cookies, now is a good time. A full portal audit should include this check.

If you haven't run a structured audit of your HubSpot portal recently, the HubSpot portal audit checklist covers cookie settings, consent configurations, and 70+ other items every admin should verify. This cookie update belongs on that list.

GDPR and CCPA Compliance Posture. An essential cookie that gets blocked due to an outdated allowlist creates a compliance gray zone. Visitors exercised their rights by declining non-essential cookies, but they're being denied a core function. That's worth a conversation with your legal or privacy team.

Key Takeaway

If your portal runs customer-facing login experiences, this update is a compliance and user experience issue, not just a technical configuration task. Check your consent platform today.

If you're actively building out your customer portal experience, this cookie update pairs with other recent Service Hub changes. The Support Space rename in Customer Portal is worth reviewing alongside this fix, since both changes affect how humans experience your customer-facing portal.

Who Should Care Most

This update is high-priority for a specific set of portals. If any of the following describes you, act now.

  • Content Hub Professional or Enterprise portals running private pages or membership-gated content where visitors log in to access materials.
  • Service Hub Professional or Enterprise portals with an active customer portal where contacts log in to view or manage support tickets.
  • Any portal operating under GDPR, CCPA, or similar privacy regulations that uses a consent management platform to control cookie behavior.
  • HubSpot admins and RevOps leads responsible for portal health, compliance, and user experience across marketing and service touchpoints.

If your portal doesn't use gated content or a customer portal, this update doesn't apply to you. But if it does, and you haven't made this fix yet, your login experience has been broken for affected visitors since August 21, 2026.

George's Take

I've seen this exact pattern play out more times than I can count. HubSpot ships a technically sound, security-positive change, and it quietly breaks something because the supporting infrastructure didn't get updated at the same time. A consent platform is third-party software. HubSpot can't update it for you. That gap is yours to own. What frustrates me isn't the update itself; it's that most portals won't catch this until a real person reports a login failure. Build a process where changes like this are on your radar before a frustrated member sends a support email. That's what proactive portal stewardship looks like.

“HubSpot can upgrade their security. They can't upgrade your consent platform for you. That gap is yours to own, and the fix takes ten minutes.”
— George B. Thomas

This update also lands in the same window as the HubSpot Customer Terms of Service update from September 2026. If you're doing a compliance review, check both at the same time. They belong in the same conversation.

If you're not sure whether your consent platform is configured correctly, or if you want a full review of how your HubSpot portal is set up for security and compliance, let's talk. The Sidekick team has reviewed hundreds of portals, and we know exactly where these gaps hide. Book a strategy call and we'll help you find the issues before your humans do.

Frequently Asked Questions

The hs-membership-csrf cookie is a CSRF security token HubSpot uses to protect logins on gated content, including private pages, customer portals, and membership sites. It's classified as an essential cookie. HubSpot replaced it with __Host-hs-membership-csrf on August 21, 2026, to apply stronger browser-level security enforcement.

Why are visitors seeing 'An unexpected error occurred' when logging into my HubSpot private pages?

If your consent management platform blocks the new __Host-hs-membership-csrf cookie because it only has the old hs-membership-csrf name in its allowlist, visitors who decline non-essential cookies can't complete login. The fix is to add the new cookie name to your essential-cookie allowlist in your consent platform.

Log in to your consent management platform (such as OneTrust, Cookiebot, or CookieYes), find your essential cookie list, and add __Host-hs-membership-csrf as an allowed essential cookie. Save and publish the change. Test login in incognito mode with non-essential cookies declined to confirm it works.

This change affects Content Hub Professional, Content Hub Enterprise, Service Hub Professional, and Service Hub Enterprise. These are the tiers that support private pages, membership sites, and customer portals, which are the features that depend on the CSRF login cookie.

It's an essential cookie. It's required for login functionality on HubSpot-gated content and customer portals. It should not be blocked by consent banners. However, consent platforms only allow cookies they've been told to allow by name, so you must update your allowlist manually to include the new cookie name.

Potentially, yes. If visitors decline non-essential cookies but are then denied access to a function that depends on an essential cookie, that creates a compliance and user experience problem. Essential cookies should work regardless of consent choices. Updating your allowlist restores the correct behavior and keeps your compliance posture clean.

Comments

Join the conversation. Share what resonated, ask questions, or add your perspective.

Leave a Comment

We'd love to hear your thoughts. Your comment will appear after review.

Never shared publicly.

0/2,000

Related Resources

Breeze Ate the Show: What HubSpot's Twenty-Eight May 22 Updates Are Telling Every AdminHubSpot Updates

Breeze Ate the Show: What HubSpot's Twenty-Eight May 22 Updates Are Telling Every Admin

HubSpot shipped 28 updates the week of May 22, 2026. Eight live inside Breeze Assistant. Here's the pattern that ate the live show, and what to do this week.

May 22, 2026

The Silos Are Crumbling: What HubSpot's May 2026 Updates Are Actually Telling YouHubSpot Updates

The Silos Are Crumbling: What HubSpot's May 2026 Updates Are Actually Telling You

HubSpot's May 2026 updates are quietly dissolving the marketing-sales-service wall. Marketing Research Agent, Breeze, GPT Image 2.0, Onboarding Plans and more.

May 15, 2026

The B2B Customer Journey In 2026: Why Most Maps Fail And How To Build One That Actually Guides BuyersArticle

The B2B Customer Journey In 2026: Why Most Maps Fail And How To Build One That Actually Guides Buyers

Most B2B customer journey maps were built for a buyer who doesn’t exist anymore. Learn how AI, dark funnel research, and HubSpot-powered systems are reshaping the 2026 journey—and how to design one that actually converts.

May 1, 2026

Abstract comic-style background

Ready To Talk?

Need Help Making Sense of HubSpot?

Sidekick Strategies helps your humans get the most out of every HubSpot update, feature, and tool. Let's make your portal work harder for you.