Registry / http-networking / cookie

cookie

JSON →
library1.1.1jsnpmunverified

The `cookie` package provides fundamental utilities for parsing and serializing HTTP `Cookie` and `Set-Cookie` headers, commonly used in Node.js HTTP servers. It is currently at stable version 1.1.1, with relatively frequent patch and minor releases addressing fixes and new HTTP cookie attributes like `partitioned` and `priority`. Key differentiators include its focus on adherence to RFC6265, minimal API surface, and robust handling of common cookie patterns. It is maintained by the `jshttp` organization, known for foundational Express.js ecosystem middleware, ensuring reliability and specification compliance.

http-networkingweb-framework
Install & Compatibility
Where this runs
tested against v? · npm install
Install × environment matrix
Each cell = how many times install + import succeeded across repeated harness runs. Partial = flaky.
glibc = Debian/Ubuntu slim · musl = Alpine Linux
musl
node 18226 runs
build_error
glibc
node 18226 runs
build_error
Code
Verified usage

Verified import paths — ran on the pinned version, not inferred.

ESM named imports are required since v1.0.0. CommonJS users should also use named imports for `parseCookie` directly or import the entire module as a namespace.

import { parseCookie } from 'cookie';

The `serialize` method was renamed to `stringifySetCookie` in v1.1.0, though `serialize` remains for backward compatibility. Always use the new named export for clarity.

import { stringifySetCookie } from 'cookie';

Introduced in v1.1.0 for parsing `Set-Cookie` headers into objects, distinct from `parseCookie` for `Cookie` headers.

import { parseSetCookie } from 'cookie';

Since v1.0.0, the package uses an `__esModule` marker, meaning default imports are no longer valid. You must use a namespace import (`import * as cookie`) or named imports for specific functions.

import * as cookie from 'cookie';

Demonstrates parsing HTTP `Cookie` headers and both parsing and stringifying `Set-Cookie` headers with common options.

import { parseCookie, stringifySetCookie, parseSetCookie } from 'cookie'; // Example 1: Parsing a 'Cookie' header from an incoming request const cookieHeader = 'foo=bar; equation=E%3Dmc%5E2; Path=/; Secure'; const parsedCookies = parseCookie(cookieHeader); console.log('Parsed Cookies:', parsedCookies); // Expected: { foo: 'bar', equation: 'E=mc^2' } // Example 2: Stringifying a 'Set-Cookie' header for an outgoing response const setCookieObject = { name: 'sessionid', value: 'abc123def456', maxAge: 3600, // 1 hour httpOnly: true, secure: true, path: '/', sameSite: 'Lax' }; const setCookieString = stringifySetCookie(setCookieObject); console.log('Set-Cookie String:', setCookieString); // Expected: sessionid=abc123def456; Max-Age=3600; Path=/; HttpOnly; Secure; SameSite=Lax // Example 3: Parsing a 'Set-Cookie' header (e.g., from a client-side response) const rawSetCookie = 'mytoken=somevalue; Max-Age=7200; Path=/api; Expires=Wed, 21 Oct 2026 07:28:00 GMT; HttpOnly'; const parsedSetCookie = parseSetCookie(rawSetCookie); console.log('Parsed Set-Cookie Object:', parsedSetCookie); // Expected: { name: 'mytoken', value: 'somevalue', maxAge: 7200, path: '/api', expires: <Date object>, httpOnly: true }
Debug
Known footguns
breakingVersion 1.0.0 introduced significant breaking changes, including minimum Node.js v18, mandatory named or namespace ESM imports, and a null prototype object for `parse` return values. The `strict` and `priority` options now require lowercase strings.
breakingThe `parse` and `serialize` methods were renamed to `parseCookie` and `stringifySetCookie` respectively in v1.1.0 to improve clarity and introduce `parseSetCookie` and `stringifyCookie`. While old names are aliased for backward compatibility, relying on them is discouraged.
gotchaWhen using `maxAge` and `expires` options together in `stringifySetCookie`, RFC6265 states `maxAge` takes precedence. However, some clients might not obey this. It's best practice to ensure both point to the same date and time if used.
breakingThe `maxAge` option in `stringifySetCookie` now strictly requires an integer value, using `Number.isInteger` for validation. Non-integer values will cause issues.
gotchaThe `cookie.parseSetCookie` method strictly follows the specification and will ignore invalid or unrecognized attributes in a `Set-Cookie` string, rather than attempting to normalize or guess their intent.
Upgrade
Version history

Breaking-change detection hasn't run for this library yet.

Audit
Security & dependencies

CVE tracking and dependency tree are planned for a later release.

Agent activity
14 hits · last 30 days
gptbot
4
googlebot
4
ahrefsbot
3
bytedance
2
script
1
Resources