Cookies (document.cookie) store tiny data the browser attaches to matching requests — historically for sessions. For auth, prefer server-set cookies with HttpOnly (hidden from JS, blocks XSS theft), Secure, and SameSite. Client-readable cookies suit non-sensitive prefs; for general storage, localStorage/IndexedDB are simpler.