Cookie
- In Turkish
- çerez
In short
A cookie is a small piece of data a website asks the browser to store and send back with later requests, often used to keep users logged in.
What is a cookie?
Because HTTP is stateless, a server has no built-in memory of who sent a request. Cookies solve this: the server includes a Set-Cookie header in a response, the browser saves the name and value, and it automatically attaches them in a Cookie header on future requests to the same site.
Cookies are commonly used for login sessions, shopping carts, language preferences, and analytics. A typical session cookie holds only a random ID that points to data stored on the server, not the user's information itself. Each cookie can have an expiration date; without one, it is deleted when the browser session ends.
Attributes control how safely a cookie behaves. HttpOnly hides it from JavaScript, which limits the damage of XSS attacks; Secure sends it only over HTTPS; and SameSite controls whether it is sent with requests coming from other sites, which is an important defense against CSRF.
It helps to think of a cookie as a coat-check ticket: the ticket is small and means nothing on its own, but the server uses it to find your coat. Cookies are often confused with localStorage, which also stores data in the browser but is never sent to the server automatically and can be read by any script on the page.
At a glance
Key takeaways
- Servers set cookies with the
Set-Cookieresponse header. - Browsers send cookies back automatically on matching requests.
- Session cookies usually store only a random ID, not user data.
HttpOnly,Secure, andSameSitemake cookies safer.- Unlike
localStorage, cookies travel to the server with every matching request.
Example
# Server response after a successful login
HTTP/1.1 200 OK
Set-Cookie: session_id=a3f9c2e1; HttpOnly; Secure; SameSite=Lax; Max-Age=86400; Path=/
# Every later request from the browser includes it automatically
GET /account HTTP/1.1
Host: example.com
Cookie: session_id=a3f9c2e1Readers ask
What is the difference between cookies and localStorage?
Cookies are sent to the server automatically with each matching request and can be hidden from JavaScript with HttpOnly. localStorage stays in the browser, holds more data, and is only read or sent by your own JavaScript code.
What are third-party cookies?
Third-party cookies are set by a domain other than the one in the address bar, such as an embedded ad or tracking script. Because they have been widely used for cross-site tracking, browsers such as Safari and Firefox block them by default.
Are cookies safe?
Cookies are plain data, not programs, so they cannot run code or infect a computer. The main risks are stolen session cookies and tracking, which are reduced with HttpOnly, Secure, SameSite, and short lifetimes.
Often compared
- Cookies vs Local StorageCookies are small data the browser sends to the server with every matching request, while local storage keeps larger data in the browser and never sends it.
- Cookie vs SessionA cookie is small data the browser stores and sends back with each request, while a session is state the server keeps about a visitor, found by a cookie ID.
See also
- HTTPWeb Development, p. 19HTTP is the protocol that browsers, apps, and servers use to exchange web pages and data through a simple cycle of requests and responses.
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- JWTSecurity, p. 19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- CSRFSecurity, p. 8CSRF is an attack that tricks a logged-in user's browser into sending an unwanted request to a trusted site, which treats it as a genuine user action.
- XSSSecurity, p. 48XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
- CORSWeb Development, p. 8CORS is a browser security mechanism that lets a server declare which other websites may read its responses when they make requests from JavaScript.
- HTTP HeaderWeb Development, p. 20An HTTP header is a name-and-value line sent with an HTTP request or response, carrying details such as the content type, caching rules or credentials.
- Session HijackingSecurity, p. 38Session hijacking is an attack in which someone steals or guesses a user's session ID or token and uses it to act as that user without knowing their password.
Sources
Spotted a mistake or something missing on this page?Suggest an edit