Session cookies are temporary cookies that exist only for the duration of a website visit. Once you close the browser, they are automatically deleted.
How do session cookies work?
Session cookies are stored in the browser's temporary memory and have no set expiry date. The browser automatically deletes them when the session ends (closing the browser or the tab).
Typical uses of session cookies
- Authentication – Maintaining login during the visit
- Shopping basket – Remembering items in the basket
- Forms – Remembering data when navigating a multi-step form
- Security tokens – CSRF protection
- Load balancing – Routing to the correct server
Session cookies vs. Persistent cookies
- Lifespan – Session cookies disappear when the browser is closed; persistent ones remain
- Expiry – Session cookies have no expiry date
- Storage – Session cookies are in memory; persistent ones are on disc
Do session cookies require consent?
Session cookies that are essential for the website to function (authentication, basket, security) do not require user consent. However, if session cookies are used for analytics or marketing, consent is required.