Sessions & Cookies
HTTP is stateless — by default, a server has no memory of who made the last request. Sessions and cookies are the two mechanisms PHP gives you to bridge that gap, which is how a site remembers you're logged in from one page to the next.
Starting a session
session_start() must run before any other output — even a stray blank line before <?php can break it, since it works by sending an HTTP header:
<?php session_start(); $_SESSION["username"] = "jamie99"; $_SESSION["cart_count"] = 3; echo "Session started for " . $_SESSION["username"]; ?>
Session started for jamie99
Behind the scenes, session_start() sends the visitor's browser a cookie containing a unique session ID, and stores $_SESSION's data on the server, keyed by that ID. The browser only ever holds the ID — the actual data stays server-side, which is why sessions are the right place for anything sensitive that a cookie alone shouldn't hold directly.
Reading session data on a later request
<?php session_start(); if (isset($_SESSION["username"])) { echo "Welcome back, " . $_SESSION["username"]; } else { echo "Please log in."; } ?>
Welcome back, jamie99
Every page that needs the logged-in visitor's data calls session_start() first, then reads $_SESSION as if it had never gone away — PHP reconnects it to the same data automatically using the session cookie the browser sends back with every request.
Ending a session: logout
<?php
session_start();
$_SESSION = [];
session_destroy();
echo "You have been logged out.";
?>
You have been logged out.
Clearing $_SESSION to an empty array and calling session_destroy() removes the server-side session data entirely — any later page that checks isset($_SESSION["username"]) will find it gone.
Cookies
A cookie, unlike session data, is stored directly in the visitor's browser and sent back with every request to the same site — useful for small, non-sensitive preferences that should persist even across separate browsing sessions:
<?php setcookie("theme", "dark", time() + (86400 * 30), "/"); $theme = $_COOKIE["theme"] ?? "light"; echo "Using theme: $theme"; ?>
Using theme: light
setcookie() takes a name, a value, an expiration time (here, 30 days from now, in seconds), and a path. Note the output still shows light on this same request — a cookie set with setcookie() only becomes readable through $_COOKIE on the next request, since it has to make a round trip to the browser first.
== versus === trap), conditionals, loops, indexed and associative arrays, functions, reading form input safely, querying a database through PDO's prepared statements, and remembering a visitor across requests with sessions and cookies. From here, the natural next steps are a real framework (Laravel or Symfony) and pairing what you've learned here with the SQL course to go deeper on the database side.