Browser Cookies: First-Party, Third-Party and Session Cookies
Cookies are small name-value records a site asks a browser to store and return under defined rules. First-party versus third-party describes the request context, while session versus persistent describes lifetime; browser privacy controls can block, partition or delete them differently.
Timeline
- When a site responds: The server can set a cookie with domain, path, lifetime, cross-site and security attributes that the browser evaluates.
- On later matching requests: The browser may return the cookie according to those attributes, request context and its own privacy policy.
- At expiration or user action: The browser removes the cookie when its lifetime ends, its policy deletes it or the user clears site data.
An HTTP cookie is a small name-value record associated with a site and stored by the browser. Sites use cookies for login sessions, shopping carts, preferences, measurement and other state that HTTP requests do not otherwise remember. The browser sends a matching cookie on later requests according to its domain, path, security, lifetime and cross-site attributes. A cookie is not automatically a person’s full browsing history, but an identifier can let a service connect multiple requests or visits. [1][2]
First-party and third-party describe context, not two different file formats. When the cookie’s site matches the page shown in the address bar, it is used in a first-party or same-site context. When an embedded image, frame, script or other request belongs to a different site, access to that site’s cookies is third-party or cross-site. The same domain can therefore be first-party when visited directly and third-party when embedded elsewhere. [1][3]
Session and persistent describe lifetime, a separate dimension. Under the HTTP rules summarized by MDN, a cookie without Expires or Max-Age is a session cookie, while one with either attribute can persist until the stated time. Browser session restoration can preserve session cookies across a restart, so “session” does not always mean deletion the instant every window closes. A first-party or third-party cookie can be either session or persistent. [2][4]
Attributes narrow when a cookie is sent or exposed. Secure restricts transmission to secure contexts; HttpOnly prevents ordinary JavaScript access while still allowing the browser to attach the cookie to requests. SameSite Strict, Lax and None control cross-site sending, and SameSite=None requires Secure. Domain and Path define matching scope but are not complete security boundaries. Well-designed authentication cookies combine restrictive scope, short lifetime and server-side protections rather than relying on one attribute. [2][4]
Browsers increasingly block or partition third-party state to reduce cross-site tracking. Partitioning gives embedded content a separate cookie jar for each top-level site, so the identifier used under one site is not automatically available under another. WebKit documents full third-party-cookie blocking in its tracking prevention system, while Chromium documents partition keys and evolving controls. Exact defaults and exceptions differ by browser, version, profile and enterprise policy, so old blanket claims become stale quickly. [3][5]
Blocking third-party cookies can improve privacy but may affect embedded sign-in, payment, video, chat or preference features that were designed around cross-site state. Modern alternatives include partitioned cookies and explicit storage-access mechanisms. If a site breaks, first use its own sign-in or consent flow and a narrow site exception if the browser offers one, rather than disabling protection everywhere. A private window also changes storage behavior but does not make the user anonymous to sites, networks or employers. [1][3][5]
Clearing cookies can sign a user out, reset preferences and empty some carts because the server loses the browser’s session identifier; it does not necessarily delete the account or every copy of data held by the service. Use browser site-data controls to inspect or clear one site before deleting everything. Consent banners describe a site’s declared uses, while browser controls determine what storage is technically allowed. Reading both is more informative than assuming every first-party cookie is necessary or every third-party cookie is advertising. [1][2][3]
Sources
- MDN — Third-Party Cookies
- MDN — Set-Cookie Header
- WebKit — Tracking Prevention
- MDN — Secure Cookie Configuration
- Chrome for Developers — Storage and Cookies