# Cookie

URL: https://softwaredictionary.org/terms/cookie
Category: Web Development
Last updated: 2026-09-29
In Turkish: çerez

In short: A cookie is a small piece of data a website asks the browser to store and send back with later requests, often used to keep users logged in.

## What is a cookie?

Because HTTP is stateless, a server has no built-in memory of who sent a request. Cookies solve this: the server includes a `Set-Cookie` header in a response, the browser saves the name and value, and it automatically attaches them in a `Cookie` header on future requests to the same site.

Cookies are commonly used for login sessions, shopping carts, language preferences, and analytics. A typical session cookie holds only a random ID that points to data stored on the server, not the user's information itself. Each cookie can have an expiration date; without one, it is deleted when the browser session ends.

Attributes control how safely a cookie behaves. `HttpOnly` hides it from JavaScript, which limits the damage of XSS attacks; `Secure` sends it only over HTTPS; and `SameSite` controls whether it is sent with requests coming from other sites, which is an important defense against CSRF.

It helps to think of a cookie as a coat-check ticket: the ticket is small and means nothing on its own, but the server uses it to find your coat. Cookies are often confused with `localStorage`, which also stores data in the browser but is never sent to the server automatically and can be read by any script on the page.

## Key takeaways

- Servers set cookies with the `Set-Cookie` response header.
- Browsers send cookies back automatically on matching requests.
- Session cookies usually store only a random ID, not user data.
- `HttpOnly`, `Secure`, and `SameSite` make cookies safer.
- Unlike `localStorage`, cookies travel to the server with every matching request.

## Example: Setting and sending a secure session cookie

```http
# Server response after a successful login
HTTP/1.1 200 OK
Set-Cookie: session_id=a3f9c2e1; HttpOnly; Secure; SameSite=Lax; Max-Age=86400; Path=/

# Every later request from the browser includes it automatically
GET /account HTTP/1.1
Host: example.com
Cookie: session_id=a3f9c2e1
```

## Frequently asked questions

**What is the difference between cookies and localStorage?**

Cookies are sent to the server automatically with each matching request and can be hidden from JavaScript with `HttpOnly`. `localStorage` stays in the browser, holds more data, and is only read or sent by your own JavaScript code.

**What are third-party cookies?**

Third-party cookies are set by a domain other than the one in the address bar, such as an embedded ad or tracking script. Because they have been widely used for cross-site tracking, browsers such as Safari and Firefox block them by default.

**Are cookies safe?**

Cookies are plain data, not programs, so they cannot run code or infect a computer. The main risks are stolen session cookies and tracking, which are reduced with `HttpOnly`, `Secure`, `SameSite`, and short lifetimes.

## Sources

- [RFC 6265: HTTP State Management Mechanism](https://www.rfc-editor.org/rfc/rfc6265.html)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
