RadiusNest › Guides

MikroTik hotspot cookies: http-cookie, MAC cookie and repeat logins

Last updated: 2 October 2026

A hotspot cookie lets a customer who has logged in once come back without typing the password again. MikroTik has two kinds, kept in the same list. They explain both "why must I log in every time?" and "why is this user back online after I removed them?".

The two kinds

HTTP cookieMAC cookie
Turned on withcookie in login-bymac-cookie in login-by
Storedin the customer's browser and on the routeron the router only, against the MAC address
Logs the customer in whenthat browser opens the login page againthe device appears on the network; no page is needed
Lifetime set byhttp-cookie-lifetime in the hotspot profilemac-cookie-timeout in the user profile
Default lifetime3 days3 days

The MAC cookie suits phones best. Their sign-in window is not the normal browser and often does not keep an HTTP cookie, so with HTTP cookies alone phone users still see the login page.

Turn on HTTP cookies

/ip hotspot profile print
/ip hotspot profile set hsprof1 login-by=cookie,http-chap,http-pap http-cookie-lifetime=1d

login-by replaces the whole list, so include the methods you already use. A cookie cannot be the only method; the customer needs a way to log in the first time.

Turn on the MAC cookie

/ip hotspot profile set hsprof1 login-by=mac-cookie,cookie,http-chap,http-pap
/ip hotspot user profile set 5M add-mac-cookie=yes mac-cookie-timeout=1d

After a successful login the router remembers the pair of username and MAC address. The next time that device connects, it is logged in as that user straight away, until the timeout passes. add-mac-cookie=no in a user profile switches it off for that plan only.

See and remove cookies

/ip hotspot cookie print

Each line shows the user, the MAC address and when it expires. Remove one user's, one device's, or all:

/ip hotspot cookie remove [find user="ali"]
/ip hotspot cookie remove [find mac-address=AA:BB:CC:DD:EE:FF]
/ip hotspot cookie remove [find]

Choosing a lifetime

  • Hourly or daily vouchers: a few hours, or off. The cookie should not outlive the visit.
  • Weekly and monthly customers: several days, so they are not asked again each morning.
  • Shared computers (a reception PC, an internet café): no HTTP cookie, or the next person is logged in as the last one.

A cookie does not extend a package. If the user is disabled, removed, or out of time or data, the cookie login is refused like any other and the login page appears.

Why users are asked to log in again

  • Neither cookie nor mac-cookie is in the profile's login-by.
  • The cookie expired. Compare the lifetime with how often the customer visits.
  • The phone has a new private MAC address. Both kinds of cookie are tied to the MAC address.
  • The customer pressed Log out on the status page. That removes the cookie on purpose.
  • The browser is in private mode or clears cookies on closing (HTTP cookie only).
  • The session ended by a timeout and no cookie method is on. See session and idle timeouts.

Why a removed user comes straight back

Removing a session from the active list does not remove the cookie. The device still holds a valid one, so it is logged in again within seconds. To really end it, remove the cookie as well; the full sequence is in disconnecting a hotspot user.

MAC cookie or MAC login?

They are easy to mix up. With the MAC cookie the customer logs in once with a username and the router remembers the device for a while. With MAC authentication there is never a username: the MAC address is the user. The cookie is the safer convenience, because it expires by itself.

With RADIUS

Cookies stay on the router whichever way users are checked. A cookie login for a RADIUS user is still sent to the server for approval, so a customer whose package has ended is not let in by an old cookie.

Where RadiusNest fits

Cookies are a router feature and RadiusNest leaves them as you set them. Each returning login is still checked centrally, so the package's speed, data, time and end date apply however the customer got back in. For a device that should never see the login page, RadiusNest has a MAC auto-login mode per customer.

Start the free trial See pricing

Questions and answers

What is the difference between cookie and mac-cookie on MikroTik?

The HTTP cookie is kept in the browser and works when the browser opens the login page. The MAC cookie is kept on the router against the device's MAC address and logs the device in as soon as it connects.

How long does a MikroTik hotspot cookie last?

Three days by default for both kinds. Change http-cookie-lifetime in the hotspot profile and mac-cookie-timeout in the user profile.

Does a cookie let an expired user back in?

No. The cookie only saves typing. The user is checked again at each login and is refused if disabled or out of time or data.

Related guides

Start the free trial See pricing