Assuming you're talking about an external or iframe Facebook application, Facebook uses OAuth2.0 and stores a cookie on your server of the form fbs_APPID, where APPID is obviously the application identifier of your connect / canvas application.
cookie access_token, API-, API- . , xdreceiver .
Facebook OAuth2.0 , access_token.