In brief
Fourteen of twenty affiliate platforms print a default cookie window: 30 days on four, 45 on one, 60 on five, 90 on four. Sixteen let you change it, ten per campaign or program. Two print a maximum of 365 days. Whatever the number, Safari caps a script-set cookie at seven days. After a decorated link from a classified domain, the cap is one day. So the number is a policy for most browsers and a week in one. The route that survives is the sale matched on the invoice.
No card. Cancel in one click.
What cookie duration do affiliate programs use?
In shortFourteen of the twenty platforms on this site's calculator print a default. The spread is narrow: 30 days on four, 45 on one, 60 on five, 90 on four. Sixteen let you change it. Two print a maximum, and both say 365 days. Whatever the number, Safari caps a cookie set by a script at seven days. After a decorated link from a domain it has classified, the cap is one day. So the default is a policy for most browsers and a ceiling of a week in one.
The research method was simple. I put four questions to twenty vendors' help centres and docs on 7 September 2026. What is the default window, in days? Can the merchant change it, and is there a maximum or a per-campaign setting? Is the cookie set on the merchant's domain, or does the link go through the vendor's first? First click or last click by default? Then I set the answers against Safari's own release notes. I found that the number founders argue over, 30 or 60 or 90, is the smaller question. Who set the cookie and how the link arrived matter more.
Three words first. A cookie window is how long after a click a sale still counts for the affiliate. A first-party cookie is one set on your own domain, by a script on your own page. Browsers treat it more kindly than one set from another domain. And last click is the rule that credits the last affiliate link a customer clicked. First click credits the first. Those three are what the four questions measure.
By default, Tapfiliate sets cookie time to 45 days, though industry standards can vary from 30 to 90 days.
| Platform | Default window | Can you change it? | Where the cookie lives | First or last click |
|---|---|---|---|---|
| AffiliateRail | 60 days | Yes, one setting; no maximum printed | First-party, by script on your domain; your own tracker domain | First click |
| Tolt | Not printed; 30 in every docs example | Not printed | Script on your domain; the docs do not say first-party | Not printed |
| Rewardful | 60 days | Yes, per campaign | First-party, by script | First touch, switchable per campaign |
| FirstPromoter | 60 days | Yes, on the campaign | Two cookies by script; the pages do not say first-party | Last click, switchable |
| Tapfiliate | 45 days | Yes, per program, maximum 365 | Query string on your domain by default | Last click |
| Affonso | 30 days | Yes, a script attribute | Cookie on your domain, read by your server | Last click, printed as fixed |
| PromoteKit | 60 days | Yes, per campaign | Cookie on your domain, read by your server | Not printed |
| Partnero | Not printed | Yes, per program | First-party, by script; a full server-side route | Both offered, default not printed |
| Trackdesk | 30 days | Yes, per offer, maximum 365 | A redirect first, then a cookie on your domain | Both offered, default not printed |
| Partli | 90 days | Not printed | A redirect on the default link; first-party on deep links | Not printed |
| Ambassly | 60 days | Yes, per program | First-party, by script | Last click |
| Dub | 90 days | Yes, a script option | A redirect first, then a first-party cookie; a reverse-proxy option | Last click, switchable |
| Komissio | Not called a default; 60 in a setup example | Not printed | First-party, on your own subdomain | Not printed |
| PartnerStack | 90 days | Not printed | A redirect through grsm.io, then first-party cookies | Last click |
| Reditus | Not printed; "common periods ranging between 30-90 days" | Yes, in the dashboard | Not printed | Not printed |
| Endorsely | 90 days | Yes, per program | A ?via= link on your domain, no redirect | Both offered, default not printed |
| LeadDyno | Not printed; a length in months, blank means indefinite | Yes, in months | Not printed | Both offered, default not printed |
| Impact.com | Not printed; set per template term | Yes, in the contract terms | A tracking link first, then first-party and third-party cookies | Last click |
| Refgrow | 30 days | Yes, in project settings | First-party, by script | Not printed |
| refVenue | 30 days | Yes, per program | A cookie on your domain, across subdomains | Not printed |
What is the typical default?
In short60 days is the most common printed default, on AffiliateRail, Rewardful, FirstPromoter, PromoteKit and Ambassly. 90 days is next, on Dub, PartnerStack, Partli and Endorsely. 30 days is on Affonso, Trackdesk, Refgrow and refVenue. Tapfiliate alone prints 45, and its help centre says why: "industry standards can vary from 30 to 90 days".
Two more show a number without calling it a default. Tolt's docs put 30 in every example. A fresh program returned 30 from its API on 20 August. But no Tolt page calls 30 the default, and a help-centre search for "cookie" returns nothing. Komissio's home page shows "Cookie window 60 days" in a setup example. Four print no number at all: Partnero, Reditus, LeadDyno and Impact. LeadDyno's setting is in months, and blank means indefinite. Impact's window is a contract term.
Let's say you want to match the middle of the market. 60 days does that. Let's say you sell a product with a long decision, such as a tool bought by a team after a month of trial. 90 days is where four platforms already sit. Tapfiliate and Trackdesk both let you go to 365, which Trackdesk explains: "All major browsers cap cookie lifetimes at a year". Let's say you sell an impulse purchase. 30 days is where four platforms sit. The number you pick is a policy on what counts as your partner's sale.
Can you change it, and per what?
In shortSixteen of twenty print that you can. Ten let you set it per campaign, program or offer. Rewardful, FirstPromoter and PromoteKit set it per campaign. Tapfiliate, Partnero, Ambassly, Endorsely and refVenue set it per program. Trackdesk sets it per offer, and Impact per template term. Affonso and Dub set it per script install. AffiliateRail, Reditus, LeadDyno and Refgrow print one setting for the whole account. Tolt, Partli, Komissio and PartnerStack print nothing about changing it.
Per campaign matters when partners differ. A newsletter sends buyers the same afternoon. A review site sends them a month later. Those are two windows, not one. On Rewardful the setting sits under the campaign's advanced settings, "enter the number of days". On FirstPromoter it is "Cookie life (days)" on the campaign, "Default is 60 days". On Dub it is a parameter on the script, so one install has one window.
The two printed maximums are both a year. Tapfiliate: "The maximum cookie time you can configure is 365 days." Trackdesk: "365 days", with the browser reason above. The other eighteen print none, which does not mean there is none. It means the page does not say. A founder who wants two years should ask before assuming the field takes it.
What does Safari do to all of this?
In shortIt shortens it. WebKit's Intelligent Tracking Prevention 2.1, from March 2019, caps cookies set through document.cookie at seven days. ITP 2.2, a month later, caps them at one day in one case. That is when the visitor arrived from a domain Safari has classified as a tracker, and the landing URL carries a query string or fragment. An affiliate link is exactly that. ITP 2.3 deletes script-writable storage after seven days without a visit. A 2020 update capped CNAME-cloaked cookies at seven days too.
So on Safari, a 60-day window set by a script is a seven-day window, and sometimes a one-day one. The vendor's number is the policy; the browser's number is the ceiling. Four vendors print their own note on it. Ambassly: Safari "can cap client-set cookies to about 7 days in common referral flows". PartnerStack: "a cookie will be capped at 7 days if the user does not return to your website". Komissio and Impact print ITP pages of their own. The other sixteen leave it to you to know.
The way round it is to stop relying on the cookie. Fifteen platforms print a server-side route. Your own server reads the click and passes it to your billing system, so the sale is matched on the invoice rather than the browser. Six print a reverse proxy or a tracker domain of your own. Then the cookie is set by your domain rather than through a third party. Dub's script option is "useful for setting up reverse proxies to avoid adblockers". AffiliateRail prints "a tracker domain of your own". The cookieless tracking article walks the whole mechanism. The Stripe tracking article shows the invoice route.
Where does the cookie live, and does the link bounce first?
In shortTen vendors say "first-party" in their own words. Five more describe a cookie on your domain without the words. Five say nothing. Separately, five send the click through the vendor's domain before yours: Dub, PartnerStack, Trackdesk, Impact, and Partli's default link. Thirteen go straight to your domain with a parameter, which is the shape Safari treats best.
The two questions are different. A cookie can be first-party and still arrive after a bounce through the vendor's domain. That is what Dub, PartnerStack and Trackdesk do: the redirect captures the click server-side, then the script on your page writes a first-party cookie. That is a sound design. It is also the shape ITP 2.2's one-day cap is aimed at, because the referring domain is a tracker's and the landing URL is decorated. A direct link with ?via=abc on your own domain has no bounce. Rewardful, PromoteKit, Endorsely and eleven others use that shape.
The attribution model is the last column. Seven default to last click, two to first, four offer both without printing a default, seven print nothing. Rewardful is the one of the big four that defaults to first touch, switchable per campaign. First touch is the same rule as first click: the first affiliate link the customer clicked gets the credit. Affonso prints its model as fixed. The Rewardful comparison covers what first touch changes for a program with several partners on the same customer.
How should you set yours?
In shortPick the number by how long your buyer takes, not by what the vendor pre-filled. Set it per campaign if your platform allows and your partners differ. Then treat the number as a policy for most browsers and a week for Safari. Put the sale on the invoice rather than the browser where you can. The number is the least important of the four questions on this page.
For example, imagine a Stripe SaaS with a 14-day trial and a review site as its main partner. A customer reads the review, starts a trial the same week and buys on day 14. A 30-day window covers that on Chrome. On Safari the cookie is gone by day eight. The sale is credited only if the platform matched the trial to the click on the server. Now imagine a newsletter partner whose readers buy the same afternoon. Every window on the table covers that, on every browser. Now imagine a partner whose audience buys three months later. Only a 90-day window covers it, and only off Safari.
A word on this site's own product, with its trade-offs. AffiliateRail's window is 60 days by default. It is one setting for the account rather than per campaign, and first click rather than last, with no printed switch. It sets a first-party cookie by script on your domain and offers a tracker domain of your own. It passes the click to Stripe or Paddle on the server so the sale is matched on the invoice. It prints no maximum. It takes 0% of every payout and pays from your own PayPal or Wise on a schedule from the $59 plan.
A 60-day window, a first-party cookie, and the sale matched on the invoice
A tracker domain of your own, server-side attribution to Stripe and Paddle, and payouts from your own PayPal or Wise at 0%. Fourteen days, no card.
Every cell on this page was read off the vendor's own pages on 7 September 2026, and the Safari figures off WebKit's release notes. "Not printed" means the pages read did not say. Settings change. Read the help centre before you rely on a row.
Common questions
What is the standard affiliate cookie duration?
There is no single standard, and the spread is narrow. Fourteen platforms print a default. Five say 60 days (AffiliateRail, Rewardful, FirstPromoter, PromoteKit, Ambassly). Four say 90 (Dub, PartnerStack, Partli, Endorsely). Four say 30 (Affonso, Trackdesk, Refgrow, refVenue), and Tapfiliate says 45. Tapfiliate's own page puts the industry range at 30 to 90.
Can I change the cookie window on my affiliate software?
On sixteen of the twenty, yes. Ten set it per campaign, program or offer. Two print a maximum, Tapfiliate and Trackdesk, both at 365 days. Tolt, Partli, Komissio and PartnerStack print nothing about changing it.
Does the cookie window work in Safari?
Not as set. WebKit's Intelligent Tracking Prevention caps cookies set by a script at seven days. The cap is one day when the visitor arrived from a classified domain on a link with a query string. Fifteen platforms print a server-side route that matches the sale on the billing event instead. Six print a reverse proxy or a tracker domain of your own.
Is a longer cookie window better?
It credits later purchases to the partner, which is a policy choice. A 90-day window suits a product bought after a long decision; a 30-day one suits an impulse purchase. On Safari the difference vanishes after a week either way. So the route that puts the sale on the invoice matters more than the number.
Where these facts come from
Fact-checked and reviewed by Jimi Barkway on 7 September 2026. Every figure above was read off the document named here on the date beside it. To contact AffiliateRail about one, email support@affiliaterail.com and the figure is corrected and the date moved.
- AffiliateRail's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Tolt's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Rewardful's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- FirstPromoter's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Tapfiliate's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Affonso's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- PromoteKit's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Partnero's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Trackdesk's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Partli's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Ambassly's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Dub's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Komissio's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- PartnerStack's developer docs on the tracking parameters and first-party cookies (its support articles on the 90-day cookie and the 7-day Safari cap were read through a reader on 7 September 2026 and answer 403 to automated checks)checked 7 September 2026
- Reditus's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Endorsely's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- LeadDyno's pricing page (its help-centre article on Affiliate Settings, the tracking length in months, was read through a reader on 7 September 2026 and answers 403 to automated checks)checked 7 September 2026
- Impact.com's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- Refgrow's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- refVenue's own pages on the cookie window: the default, the setting, where the cookie lives, and the attribution modelchecked 7 September 2026
- WebKit, ITP 2.1 (21 March 2019): cookies set through document.cookie capped at seven dayschecked 4 September 2026
- WebKit, ITP 2.2 (24 April 2019): capped at one day after a decorated link from a classified domainchecked 4 September 2026
- WebKit, ITP 2.3 (23 September 2019): script-writable storage deleted after seven days without interactionchecked 4 September 2026
- WebKit, CNAME cloaking defence (12 November 2020): CNAME-cloaked cookies capped at seven dayschecked 4 September 2026