A cookie is a small piece of data a website stores in your browser so it can remember you between requests. This guide explains exactly what cookies are, how they work, the different types, what they are used for, and why they matter for privacy and securi
Almost every website you visit uses cookies, and browsers constantly ask you to accept them. Yet most people have never been told what a cookie actually is, what it stores, or why it matters. This guide explains cookies from the ground up: the problem they were invented to solve, exactly how they travel between your browser and a website, the different types that exist, how they are used in the real world, and what they mean for your privacy and security.
By the end you will understand not just the marketing pop-up that asks you to "Accept all", but the underlying technology that powers logins, shopping carts, saved preferences, and much of the modern web.
A cookie is a small piece of text that a website asks your browser to store on your device. Each cookie is essentially a name and a value, for example session_id = 8f3a9c2b, along with some rules about when and where the browser is allowed to send it back. Cookies are tiny by design. A single cookie is limited to roughly four kilobytes, which is about the size of one page of plain text.
The reason cookies exist comes down to how the web fundamentally works. The web runs on a protocol called HTTP, and HTTP is stateless. That means every request your browser makes is treated as completely independent, with no memory of the request before it. When you load a page, the server answers and then immediately forgets you exist. Without some way to remember you, a website could never keep you logged in, remember what is in your cart, or recall that you prefer dark mode.
Cookies solve that problem. They give the stateless web a memory. The browser stores a small identifier or preference and automatically sends it back with every future request to that same site, so the server can recognise you and pick up where you left off.
The cookie was invented in 1994 by Lou Montulli, an engineer at Netscape, the company behind one of the first popular web browsers. He was building an online store and needed a way for the server to remember what a shopper had placed in their basket without storing everything on the server itself. The name comes from an older computing term, the "magic cookie", a small token of data passed between programs. The idea worked, it spread to every browser, and it has remained one of the core building blocks of the web ever since.
The cookie process is a simple back and forth between a website's server and your browser. It happens in the background every time you browse, and it follows a clear sequence.
Step 1 — The server sets the cookie.
When you first visit a site, the server can include a special instruction in its response called a
Set-Cookie header. For example, the server might reply with:
Set-Cookie: session_id=8f3a9c2b; Max-Age=3600; Path=/; Secure; HttpOnly
Step 2 — The browser stores the cookie.
Your browser reads that header and saves the cookie in its cookie store, along with which website it
belongs to and the rules attached to it.
Step 3 — The browser sends it back automatically.
On every later request to that same website, the browser automatically attaches the cookie in a
Cookie header, without you doing anything. The server reads it, recognises you, and
responds accordingly, for example by keeping you logged in.
You never see any of this happening. It is all handled silently between the browser and the server on
each page load.
A cookie is more than just a name and value. It carries a set of attributes that control how it behaves. Understanding these attributes is the key to really understanding cookies, and they are also central to security.
Name and Value
The actual data being stored, such as theme=dark or cart_id=44921. In practice the value
is often not readable information but a random reference code that points to real data stored safely on
the server.
Domain
Specifies which website the cookie belongs to. The browser will only send the cookie back to that domain,
so a cookie set by one website is never sent to another.
Path
Limits the cookie to a specific section of the site. A path of /account means the cookie is only
sent when you are browsing pages under that folder.
Expires / Max-Age
Controls how long the cookie lives. This is what separates a temporary session cookie from a long lasting
persistent cookie, explained in the next section.
Secure
Tells the browser to only send the cookie over an encrypted HTTPS connection, never over plain,
unencrypted HTTP. This protects the cookie from being intercepted.
HttpOnly
Prevents JavaScript running in the page from reading the cookie. This is a critical protection that stops
malicious scripts from stealing sensitive cookies such as login sessions.
SameSite
Controls whether the cookie is sent when you arrive from another website. It has three settings, Strict,
Lax, and None, and it is one of the main defences against a class of attack called cross site request
forgery, covered later in this guide.
Cookies fall into two broad groups based on how long they last.
Session cookies have no expiry date set. They live only for as long as your browsing session, and they are deleted the moment you close the browser. These are typically used for things that only need to last while you are actively using a site, such as keeping you logged in during a single visit or holding items in a cart before checkout.
Persistent cookies have a specific expiry date or maximum age, so they survive after you close the browser and remain until that date arrives or you clear them manually. These remember longer term preferences, such as your language choice, whether you have already dismissed a notice, or a "remember me" login that keeps you signed in across days or weeks.
This distinction is at the heart of the privacy debate around cookies.
First-party cookies are set by the website you are actually visiting, the one shown in your address bar. These are the helpful, functional cookies that keep you logged in, remember your cart, and store your settings. They are generally uncontroversial because they serve the site you chose to use.
Third-party cookies are set by a different domain than the one you are visiting, usually because the page loads content from elsewhere, such as an advertising network, a social media button, or an embedded video. Because the same advertising network appears on thousands of different websites, its third-party cookie can recognise you across all of them and build a profile of your browsing habits. This cross-site tracking is what powers targeted advertising, and it is exactly what privacy regulations and browsers have moved to restrict. Major browsers are in the process of phasing out third-party cookies entirely.
Cookies serve a wide range of purposes, which is why they are so common. The most important uses include:
Authentication and sessions — keeping you logged in as you move from page to page, so you
do not have to enter your password on every click.
Shopping carts — remembering the products you have added while you continue shopping.
Preferences — storing choices such as language, currency, region, or dark mode.
Analytics — helping site owners understand how many people visit, which pages are popular,
and how visitors move through the site so it can be improved.
Advertising and tracking — recording interests and behaviour to show targeted ads, which
is the most privacy-sensitive use.
Cookies are not the only way a browser can store data. Modern browsers also offer localStorage and sessionStorage, which can hold much more data, around five to ten megabytes compared to a cookie's four kilobytes.
The key difference is behaviour. Cookies are sent to the server automatically with every request, which makes them ideal for things the server needs to know, such as who you are logged in as. Local storage is never sent to the server on its own. It stays in the browser and is only read by JavaScript on the page, which makes it better for storing larger amounts of data that only the front end needs. In short, use cookies when the server must be involved, and local storage when it does not.
Because some cookies can be used to track people across the web, they are regulated by privacy laws around the world. In Europe this is governed by the GDPR, and in South Africa by the Protection of Personal Information Act, known as POPIA. These laws generally require that websites tell you what cookies they use and, for non-essential cookies such as analytics and advertising, obtain your consent before setting them.
This is why you constantly see cookie banners asking you to accept or manage your preferences. Strictly necessary cookies, the ones required for the site to function at all, such as keeping you logged in, usually do not require consent. Tracking and marketing cookies do. For South African businesses, handling cookies correctly is part of staying POPIA compliant and building trust with visitors.
Because cookies often hold the key to your logged-in session, they are a valuable target for attackers. There are three risks worth understanding, along with the protections that guard against them.
Session hijacking happens if an attacker manages to steal your session cookie, because they
can then impersonate you without needing your password. The Secure attribute defends against this by
ensuring cookies only travel over encrypted connections.
Cross-site scripting (XSS) is when a malicious script injected into a page tries to read your
cookies. The HttpOnly attribute defends against this by hiding sensitive cookies from JavaScript
entirely.
Cross-site request forgery (CSRF) tricks your browser into sending a request to a site where
you are logged in, using your cookie without your knowledge. The SameSite attribute defends against
this by refusing to send the cookie on requests that originate from other websites.
Used together, Secure, HttpOnly, and SameSite make cookies far safer, which is why any well-built website sets them on its important cookies.
You are always in control of the cookies stored on your device. In any modern browser you can open the settings and find a privacy or cookies section where you can view stored cookies, delete them, or block them. Developers can inspect cookies in detail by opening the browser's developer tools and looking under the Application or Storage tab, which lists every cookie and all of its attributes for the current site.
Clearing your cookies will log you out of websites and reset your saved preferences, because you are deleting the very data that let those sites remember you. That is usually harmless and sometimes useful for troubleshooting, but it is worth understanding before you do it.
A cookie is a small piece of data a website stores in your browser so that the otherwise forgetful web can remember you between requests. Cookies power logins, shopping carts, and saved preferences, and they also make analytics and advertising possible. They come in short-lived session and longer-lived persistent forms, and in first-party cookies that serve the site you are on versus third-party cookies used to track you across sites. Their attributes, especially Secure, HttpOnly, and SameSite, determine how safe they are, and privacy laws such as POPIA and GDPR govern how they may be used.
For a business, getting cookies right is not just a technical detail. It affects security, legal compliance, and the trust your visitors place in your website. If you would like your website audited for correct and compliant cookie handling, or built properly from the start, speak to our team for a professional consultation.