How it works
Both store text keys and values for one site (strictly, one origin), through calls such as localStorage.setItem('theme', 'dark'). localStorage keeps data until the site or the user clears it; sessionStorage lasts only as long as the tab. Browsers allow about 5 MB per site, and anything that is not text, such as an object, has to be turned into a JSON string first.
The API is synchronous, so large reads and writes can briefly freeze the page, and it is not available in service workers; IndexedDB suits larger or structured data. Any script on the page can read it, so a cross-site scripting (XSS) bug exposes everything inside, which is why sign-in tokens are safer in an HttpOnly cookie. Nothing stored here is sent to the server automatically.
localStorage and sessionStorage pricing
localStorage and sessionStorage vs the alternatives
Related terms
More in How the web works
In the browser