How the web works · Concept

Cookies

Small pieces of data a website asks the browser to keep and send back with every request, mostly used to keep people signed in and remember their choices.

In the browser · updated

How it works

A server sets a cookie with a Set-Cookie header, and the browser sends it back automatically on every later request to that site until it expires. That is how a site recognises you from page to page, since HTTP itself forgets. Each cookie holds only about 4 KB, and because cookies travel with every request, stuffing them with data slows the site down.

Attributes control the risks: HttpOnly hides a cookie from JavaScript, so an XSS attack cannot steal the session; Secure sends it only over HTTPS; and SameSite limits sending it from other sites, which blocks most CSRF attacks. Third-party cookies, set by a domain other than the one in the address bar, are how ad networks follow people across sites, and Safari and Firefox block or isolate them by default. In the EU and UK, non-essential cookies need consent first, which is why cookie banners exist.

Cookies vs the alternatives

More in How the web works

In the browser

All 20 How the web works terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.