How it works
A server sets a cookie with a Set-Cookie header, and the browser sends it back automatically on every later request to that site until it expires. That is how a site recognises you from page to page, since HTTP itself forgets. Each cookie holds only about 4 KB, and because cookies travel with every request, stuffing them with data slows the site down.
Attributes control the risks: HttpOnly hides a cookie from JavaScript, so an XSS attack cannot steal the session; Secure sends it only over HTTPS; and SameSite limits sending it from other sites, which blocks most CSRF attacks. Third-party cookies, set by a domain other than the one in the address bar, are how ad networks follow people across sites, and Safari and Firefox block or isolate them by default. In the EU and UK, non-essential cookies need consent first, which is why cookie banners exist.
Cookies vs the alternatives
Related terms
More in How the web works
In the browser