1. Sessions

📌 Example:

Set-Cookie: sessionid=abc123; HttpOnly; Secure

🔴 Pentesting Risks


2. Tokens vs Sessions

✅ Advantage → scalable for APIs and microservices.


3. JSON Web Tokens (JWT)