An example that springs to mind is a CSRF token [1]. One might use a session cookie so that the server can have a CSRF token on any forms. In this way we still require a session to be present even if the user doesn't have to login.
It correctly suggests putting CSRF tokens in either hidden fields or custom request headers. If you're putting the token in to a cookie then you're persisting it for some length of time beyond the existence of the page, in which case you've broken your CSRF token mechanism because they're not supposed to persist across multiple requests. You should generate a new token for every request.
You could also handle this stateless without the session using encryption or HMAC, but then you need to manage secret keys and not screw up.
https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Re...