Skip to main content

Cookie

In Turkish
çerez
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/cookie

In short

A cookie is a small piece of data a website asks the browser to store and send back with later requests, often used to keep users logged in.

What is a cookie?

Because HTTP is stateless, a server has no built-in memory of who sent a request. Cookies solve this: the server includes a Set-Cookie header in a response, the browser saves the name and value, and it automatically attaches them in a Cookie header on future requests to the same site.

Cookies are commonly used for login sessions, shopping carts, language preferences, and analytics. A typical session cookie holds only a random ID that points to data stored on the server, not the user's information itself. Each cookie can have an expiration date; without one, it is deleted when the browser session ends.

Attributes control how safely a cookie behaves. HttpOnly hides it from JavaScript, which limits the damage of XSS attacks; Secure sends it only over HTTPS; and SameSite controls whether it is sent with requests coming from other sites, which is an important defense against CSRF.

It helps to think of a cookie as a coat-check ticket: the ticket is small and means nothing on its own, but the server uses it to find your coat. Cookies are often confused with localStorage, which also stores data in the browser but is never sent to the server automatically and can be read by any script on the page.

At a glance

On a first visit the browser asks for the home page and the server answers with a Set-Cookie header, theme=dark. The browser stores the cookie and, on every later request to the same site, such as GET /about, sends it back in a Cookie header, so the server remembers the choice.BrowserServerGET /200 OK · Set-Cookie: theme=darktheme=darkSaved for this siteGET /about · Cookie: theme=darksent with every request200 OK · page in the dark theme
The server asks once with Set-Cookie; from then on the browser sends the cookie back with every request to that site, until it expires.

Key takeaways

  • Servers set cookies with the Set-Cookie response header.
  • Browsers send cookies back automatically on matching requests.
  • Session cookies usually store only a random ID, not user data.
  • HttpOnly, Secure, and SameSite make cookies safer.
  • Unlike localStorage, cookies travel to the server with every matching request.

Example

Setting and sending a secure session cookiehttp
# Server response after a successful login
HTTP/1.1 200 OK
Set-Cookie: session_id=a3f9c2e1; HttpOnly; Secure; SameSite=Lax; Max-Age=86400; Path=/

# Every later request from the browser includes it automatically
GET /account HTTP/1.1
Host: example.com
Cookie: session_id=a3f9c2e1

Readers ask

What is the difference between cookies and localStorage?

Cookies are sent to the server automatically with each matching request and can be hidden from JavaScript with HttpOnly. localStorage stays in the browser, holds more data, and is only read or sent by your own JavaScript code.

What are third-party cookies?

Third-party cookies are set by a domain other than the one in the address bar, such as an embedded ad or tracking script. Because they have been widely used for cross-site tracking, browsers such as Safari and Firefox block them by default.

Are cookies safe?

Cookies are plain data, not programs, so they cannot run code or infect a computer. The main risks are stolen session cookies and tracking, which are reduced with HttpOnly, Secure, SameSite, and short lifetimes.

Often compared

See also

Sources

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings