Cookies vs Local Storage vs Session Storage — What's the Difference?

All three store data in the browser, but differ in size limits, lifetime, and whether they're automatically sent to the server with every request.

Published October 4, 2026

All three store data in the browser, but differ in size limits, lifetime, and whether they're automatically sent to the server with every request.

Why they differ

  • Cookies are small (about 4KB) and automatically included in every HTTP request to their domain, making them suitable for session identifiers
  • Local storage persists indefinitely (until explicitly cleared) and holds several megabytes, but is never sent to the server automatically
  • Session storage behaves like local storage but is cleared when the browser tab is closed

How to choose

  • Use cookies specifically for data the server needs on every request, like a session ID, ideally marked HttpOnly and Secure
  • Use local storage for larger client-only data that should persist across sessions, like a saved theme preference
  • Use session storage for temporary, per-tab state that shouldn't persist once the tab closes

FAQ

Which is most secure for storing an auth token?

An HttpOnly, Secure cookie is generally considered safer than local storage, since HttpOnly cookies can't be read by JavaScript at all, reducing exposure to XSS attacks.

More JavaScript articles