Cookie
BackendA small value the browser attaches to every request.
How a stateless protocol manages to remember you. The browser stores it and sends it automatically with each request to that site. Marking one HttpOnly prevents JavaScript from reading it, which stops an injected script stealing a session.
See also Session, HttpOnly, JWT
HttpOnly
BackendA cookie flag that hides it from JavaScript.
Marks a cookie unreadable by page scripts, so a single injected script cannot steal a session. Tokens stored in local storage have no equivalent protection.
See also Cookie, Session
Session
BackendThe server-side record that you are logged in.
A stored record the server looks up on each request using an id from a cookie. Slower than a signed token because of the lookup, but logging out is instant and reliable.
See also Cookie, JWT, Authentication
Stateless
BackendEach request starts from nothing.
The server remembers nothing about you between requests by default. Memory has to be added deliberately, which is exactly what cookies and sessions are for.
See also HTTP, Session, Serverless