Cookies are tiny pieces of data that a website saves in your browser. You’ve probably used them without thinking about them. A cookie can remember that you logged in, keep something in your shopping cart, or tell a site that you’ve visited before.

Session Cookies and Persistent Cookies

Start with the easiest split. Session cookies live only while your browser session is open. Close the browser and they’re usually gone. They’re handy for things like keeping you logged in while moving between pages.

First-Party and Third-Party Cookies

First-party cookies come directly from the website you’re visiting. If you open an online store and that store saves a cookie in your browser, that’s first-party. They’re generally used for things the site itself needs to remember.

Third-party cookies are different. They come from another domain that’s connected to the page you’re viewing. Advertising networks have traditionally used them to track activity across different websites, which is why privacy concerns around these cookies have grown so much.

Honestly, third-party tracking is the cookie use I like least. Personalisation sounds nice until you notice the same ad following you around the internet.

Secure and HttpOnly Cookies

Some cookie types are defined by security settings rather than by how long they last or who created them. A Secure cookie is sent only over an encrypted HTTPS connection. That makes it harder for someone to intercept the cookie while data is moving between your browser and a website.

HttpOnly cookies have another job. JavaScript running in the browser can’t directly access them. This is especially useful for session cookies because it reduces the damage certain browser-based attacks could cause.

Other Cookie Settings You’ll See

A cookie can also have a SameSite setting. This controls when the browser sends the cookie along with requests involving another site. It sounds technical, but it matters for both privacy and security.

• SameSite is especially important for protecting login sessions from certain cross-site attacks.

• Secure means the cookie travels through HTTPS only, which is exactly what you want for sensitive sessions.

• HttpOnly stays out of JavaScript’s reach, a small setting with a pretty useful security benefit.

Why Websites Use So Many Cookie Types

The different types exist because websites have different things to remember. A shopping site needs your cart to survive page changes. A login system needs to recognise your session. An analytics service may want to understand how visitors move through a site.