# Cookie vs Session

URL: https://softwaredictionary.org/compare/cookie-vs-session
Last updated: 2026-10-02

In short: A cookie is small data the browser stores and sends back with each request, while a session is state the server keeps about a visitor, found by a cookie ID.

## What is the difference between a cookie and a session?

A cookie is a name and value, such as `theme=dark`, that a server asks the browser to store with the `Set-Cookie` header. From then on the browser sends it back automatically with each request to that site, until it expires or is deleted. A session is what the server remembers about a visitor, such as who is logged in or what is in their cart, kept in server memory, a database or a store like Redis.

The key difference is where the data lives. A cookie's contents travel between the browser and the server, so each cookie is limited to about 4 KB and its value can be seen, and changed, by the user. Session data stays on the server; the browser holds only a long, random session ID, which the server uses to look the data up on every request.

They usually work together rather than against each other. The most common way to carry the session ID is a cookie marked `HttpOnly`, `Secure` and `SameSite`, so scripts on the page cannot read it and it is only sent over HTTPS. The alternative to server-side sessions is to put signed data in the token itself, as JWTs do, which removes the lookup but makes it harder to end a login early.

A common misconception is that cookies and sessions are competing ways to log users in. A cookie is a storage and transport mechanism in the browser, a session is state on the server, and a typical login uses both. Storing secrets such as passwords or user roles in a plain cookie is a security mistake.

| Aspect | Cookie | Session |
| --- | --- | --- |
| Where the data lives | In the browser | On the server |
| What the browser holds | The data itself | Only a random session ID, usually in a cookie |
| Size | About 4 KB per cookie | Limited only by the server's storage |
| Visible to the user | Yes: it can be read and edited in the browser | No: the user only sees the ID |
| Lifetime | Until its expiry date, or until the browser closes | Until the server ends it or it times out |
| Cost on the server | None; nothing is stored | Memory or a shared store, read on every request |
| Typical use | Preferences, consent choices, carrying the session ID | Logins, shopping carts, multi-step forms |

## Choose Cookie when

- You need to remember a small, non-secret value such as a language or theme choice.
- The value must survive without anything stored on the server.
- You are carrying a session ID or a token between the browser and the server.

## Choose Session when

- You keep anything sensitive, such as who is logged in or what they may do.
- The data is larger than a few kilobytes.
- You need to be able to end a login on the server immediately.

## Frequently asked questions

**Are sessions stored in cookies?**

Usually only the session ID is. The session data itself stays on the server, and the cookie just tells the server which record belongs to this browser.

**Are cookies safe for logins?**

A cookie that holds a random session ID is safe when it is marked HttpOnly, Secure and SameSite. Putting passwords, roles or other trusted data in a readable cookie is not.

**What happens to a session when the browser closes?**

It depends on the cookie. A session cookie without an expiry date is deleted when the browser closes, which ends the session for the user; the server removes its copy when the session times out.

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
