Privacy

Session cookie

Also called transient cookie.

Session cookie is a cookie with no expiry date, so the browser drops it when the session ends. Carts and logins often use one.

How it is measured

In the storage panel, the Expires column reads "Session". Close the browser and the cookie should vanish, though some browsers restore sessions and keep it.

List them with their purpose. A session cookie that carries a tracking ID is still a tracking cookie for consent purposes.

Worked example

A shop keeps cart contents in a session cookie. A visitor closes the tab and reopens it ten minutes later. The cart is gone in one browser and still there in another that restored tabs.

The shop moves the cart into a server record tied to the account. Behavior is now the same everywhere.

How it differs

A session cookie is temporary by lifetime. A first-party cookie is a statement about which domain set it. A session cookie can be first party, and the two labels answer different questions.

Common errors

Assuming no consent is ever needed. Expecting it to always disappear. Putting a tracking ID in it. Confusing it with an analytics session. Skipping Secure and HttpOnly.

In practice

Use session cookies for carts and logins only. Mark them HttpOnly and Secure. Check the list after each plugin install.

See also

First-party cookie, Persistent cookie, Session

Sources

Count this on a real site.

Watch my website