In more detail
Because HTTP is stateless, a session cookie is how a site recognises you after you log in. Security attributes matter: Secure (HTTPS only), HttpOnly (hidden from scripts) and SameSite (limits cross-site sending). Third-party cookies, set by other sites embedded in a page, are used for tracking and are being phased out by many browsers.