Side by side
CookievsSession
What is the difference between a cookie and a session?
Updated 3 min read7 differences
In short
A cookie is small data the browser stores and sends back with each request, while a session is state the server keeps about a visitor, found by a cookie ID.
Cookie
A cookie is a small piece of data a website asks the browser to store and send back with later requests, often used to keep users logged in.
Read the page on CookieSession
A session is a way for a server to remember a user across many requests, usually by keeping their data on the server and giving the browser a session ID.
Read the page on SessionCookie and Session compared
| Aspect | Cookie | Session |
|---|---|---|
| Where the data lives | In the browser | On the server |
| What the browser holds | The data itself | Only a random session ID, usually in a cookie |
| Size | About 4 KB per cookie | Limited only by the server's storage |
| Visible to the user | Yes: it can be read and edited in the browser | No: the user only sees the ID |
| Lifetime | Until its expiry date, or until the browser closes | Until the server ends it or it times out |
| Cost on the server | None; nothing is stored | Memory or a shared store, read on every request |
| Typical use | Preferences, consent choices, carrying the session ID | Logins, shopping carts, multi-step forms |
The difference, explained
A cookie is a name and value, such as theme=dark, that a server asks the browser to store with the Set-Cookie header. From then on the browser sends it back automatically with each request to that site, until it expires or is deleted. A session is what the server remembers about a visitor, such as who is logged in or what is in their cart, kept in server memory, a database or a store like Redis.
The key difference is where the data lives. A cookie's contents travel between the browser and the server, so each cookie is limited to about 4 KB and its value can be seen, and changed, by the user. Session data stays on the server; the browser holds only a long, random session ID, which the server uses to look the data up on every request.
They usually work together rather than against each other. The most common way to carry the session ID is a cookie marked HttpOnly, Secure and SameSite, so scripts on the page cannot read it and it is only sent over HTTPS. The alternative to server-side sessions is to put signed data in the token itself, as JWTs do, which removes the lookup but makes it harder to end a login early.
A common misconception is that cookies and sessions are competing ways to log users in. A cookie is a storage and transport mechanism in the browser, a session is state on the server, and a typical login uses both. Storing secrets such as passwords or user roles in a plain cookie is a security mistake.
Which one should you use?
Choose Cookie when…
- You need to remember a small, non-secret value such as a language or theme choice.
- The value must survive without anything stored on the server.
- You are carrying a session ID or a token between the browser and the server.
Choose Session when…
- You keep anything sensitive, such as who is logged in or what they may do.
- The data is larger than a few kilobytes.
- You need to be able to end a login on the server immediately.
Remembering a visitor (Node.js with Express)
// Cookie: the value itself lives in the browser
app.get("/prefs", (req, res) => {
res.cookie("theme", "dark", { maxAge: 365 * 24 * 60 * 60 * 1000, sameSite: "lax" });
res.send("Saved");
});
// Later requests carry it back (read with cookie-parser):
// req.cookies.theme === "dark"// Session: the data stays on the server, the browser gets only an ID
import session from "express-session";
app.use(session({
secret: process.env.SESSION_SECRET,
resave: false,
saveUninitialized: false,
cookie: { httpOnly: true, secure: true, sameSite: "lax" },
}));
app.post("/login", (req, res) => {
req.session.userId = 42; // stored server-side
res.send("Logged in");
});Readers ask
Are sessions stored in cookies?
Usually only the session ID is. The session data itself stays on the server, and the cookie just tells the server which record belongs to this browser.
Are cookies safe for logins?
A cookie that holds a random session ID is safe when it is marked HttpOnly, Secure and SameSite. Putting passwords, roles or other trusted data in a readable cookie is not.
What happens to a session when the browser closes?
It depends on the cookie. A session cookie without an expiry date is deleted when the browser closes, which ends the session for the user; the server removes its copy when the session times out.