MikroTik hotspot cookies: http-cookie, MAC cookie and repeat logins
Last updated: 2 October 2026
A hotspot cookie lets a customer who has logged in once come back without typing the password again. MikroTik has two kinds, kept in the same list. They explain both "why must I log in every time?" and "why is this user back online after I removed them?".
The two kinds
| HTTP cookie | MAC cookie | |
|---|---|---|
| Turned on with | cookie in login-by | mac-cookie in login-by |
| Stored | in the customer's browser and on the router | on the router only, against the MAC address |
| Logs the customer in when | that browser opens the login page again | the device appears on the network; no page is needed |
| Lifetime set by | http-cookie-lifetime in the hotspot profile | mac-cookie-timeout in the user profile |
| Default lifetime | 3 days | 3 days |
The MAC cookie suits phones best. Their sign-in window is not the normal browser and often does not keep an HTTP cookie, so with HTTP cookies alone phone users still see the login page.
Turn on HTTP cookies
/ip hotspot profile print
/ip hotspot profile set hsprof1 login-by=cookie,http-chap,http-pap http-cookie-lifetime=1dlogin-by replaces the whole list, so include the methods you already use. A cookie cannot be the only method; the customer needs a way to log in the first time.
Turn on the MAC cookie
/ip hotspot profile set hsprof1 login-by=mac-cookie,cookie,http-chap,http-pap
/ip hotspot user profile set 5M add-mac-cookie=yes mac-cookie-timeout=1dAfter a successful login the router remembers the pair of username and MAC address. The next time that device connects, it is logged in as that user straight away, until the timeout passes. add-mac-cookie=no in a user profile switches it off for that plan only.
See and remove cookies
/ip hotspot cookie printEach line shows the user, the MAC address and when it expires. Remove one user's, one device's, or all:
/ip hotspot cookie remove [find user="ali"]
/ip hotspot cookie remove [find mac-address=AA:BB:CC:DD:EE:FF]
/ip hotspot cookie remove [find]Choosing a lifetime
- Hourly or daily vouchers: a few hours, or off. The cookie should not outlive the visit.
- Weekly and monthly customers: several days, so they are not asked again each morning.
- Shared computers (a reception PC, an internet café): no HTTP cookie, or the next person is logged in as the last one.
A cookie does not extend a package. If the user is disabled, removed, or out of time or data, the cookie login is refused like any other and the login page appears.
Why users are asked to log in again
- Neither
cookienormac-cookieis in the profile'slogin-by. - The cookie expired. Compare the lifetime with how often the customer visits.
- The phone has a new private MAC address. Both kinds of cookie are tied to the MAC address.
- The customer pressed Log out on the status page. That removes the cookie on purpose.
- The browser is in private mode or clears cookies on closing (HTTP cookie only).
- The session ended by a timeout and no cookie method is on. See session and idle timeouts.
Why a removed user comes straight back
Removing a session from the active list does not remove the cookie. The device still holds a valid one, so it is logged in again within seconds. To really end it, remove the cookie as well; the full sequence is in disconnecting a hotspot user.
MAC cookie or MAC login?
They are easy to mix up. With the MAC cookie the customer logs in once with a username and the router remembers the device for a while. With MAC authentication there is never a username: the MAC address is the user. The cookie is the safer convenience, because it expires by itself.
With RADIUS
Cookies stay on the router whichever way users are checked. A cookie login for a RADIUS user is still sent to the server for approval, so a customer whose package has ended is not let in by an old cookie.
Where RadiusNest fits
Cookies are a router feature and RadiusNest leaves them as you set them. Each returning login is still checked centrally, so the package's speed, data, time and end date apply however the customer got back in. For a device that should never see the login page, RadiusNest has a MAC auto-login mode per customer.
Start the free trial See pricing
Questions and answers
What is the difference between cookie and mac-cookie on MikroTik?
The HTTP cookie is kept in the browser and works when the browser opens the login page. The MAC cookie is kept on the router against the device's MAC address and logs the device in as soon as it connects.
How long does a MikroTik hotspot cookie last?
Three days by default for both kinds. Change http-cookie-lifetime in the hotspot profile and mac-cookie-timeout in the user profile.
Does a cookie let an expired user back in?
No. The cookie only saves typing. The user is checked again at each login and is refused if disabled or out of time or data.