Skip to content
Skip to main content
Accounts & Identity Technical Explainer

What is a session cookie?

A session cookie is a small piece of browser-held data that helps a website recognise an existing logged-in session.

It is usually not the account password. It is more like a continuing reference to authenticated access that has already been granted.

That matters because an account can keep being used without another password entry.

What happens after login?

A simplified sequence looks like this:

AuthenticationLogin acceptedThe service verifies the account under its rules.
Session createdServer records authenticated stateA session identifier or token is associated with the account.
Cookie storedBrowser keeps session dataThe browser can prove which session it belongs to.
Later requestsBrowser sends the cookieThe user moves through the site without signing in again each time.

This is why a browser can remain signed in for days or weeks.

What can be useful to an investigator?

Depending on the browser and service, useful details may include:

  • cookie or token name;
  • domain;
  • storage location;
  • creation time;
  • expiry time;
  • session identifier;
  • account association;
  • browser profile; and
  • surrounding browsing history.

A recovered cookie may help explain why account activity happened without a fresh login.

Suppose the account was authenticated on Monday.

The browser may still be using the same session on Friday.

If disputed activity happens on Friday, you may find no fresh password event at all.

That does not mean the Friday activity is unexplained. It means you need to follow the continuing session.

What is a login session? explains that wider relationship.

A shared computer may retain a live session.

A device may be stolen or remotely controlled.

Session material may sometimes be copied and reused elsewhere.

So the presence of a session cookie can show that the browser held authenticated session material, but you still need to work out who controlled the device or session when the relevant activity occurred.

Do not activate a live session casually

Opening an existing session may alter account state, trigger security events, synchronise data or notify the provider or user.

If live access is genuinely needed, treat that as a deliberate investigative action rather than simply clicking through.

The practical point is: a session cookie can explain continued account access without another password event. Use it to connect browser activity to a session, then attribute the use of that session separately.

Reference: AI-020Accounts & Identity