NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #483 most downloaded on crates.io
HTTP cookie parsing and cookie jar management. Supports signed and private (encrypted, authenticated) jars.
Last release 2 months ago
08 Aug 2026
Release timing varies
gaps range from 2 weeks to 2.4 years
Some releases are documented
notes for 17 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
78 releases · first in 2014
Stopped using internal time APIs.
Stopped using internal time APIs.
Expires parsing is more RFC 6265-compliant.
69 is 2069 (not 1969).The manifest now declares rust-version = "1.56".
Added support for the draft Partitioned attribute.
Added support for the draft Partitioned attribute.
The new CookieBuilder::partition(), Cookie::partitioned(), and
Cookie::set_partitioned() methods allow enabling and/or disabling the
attribute. Additionally, the attribute is recognized during parsing.
Added CookieBuilder::removal(), counterpart to Cookie::make_removal().
One column per quarter.
CookieBuilder::finish() was deprecated in favor of CookieBuilder::build().
The MSRV is now 1.56.
Cookie::value() no longer trims surrounding double quotes. (89eddd)
Use Cookie::value_trimmed() for the previous behavior.
Many methods now expect a T: Into<Cookie> in place of Cookie. (49ff7b)
Functions and methods that previously accepted a Cookie now accept any T: Into<Cookie>. This particularly affects the CookieJar API, which now allows
simpler addition and removal of cookies:
jar.add(("foo", "bar"));jar.add(Cookie::build(("foo", "bar")).path("/"));jar.remove("foo");jar.remove(Cookie::build("foo").path("/"));CookieJar::force_remove() now expects a T: AsRef<str> in place of
&Cookie.
Force-removal never requires more information than a cookie's name. The API has been simplified to reflect this.
CookieBuilder::finish() was deprecated in favor of
CookieBuilder::build().
This largely serves as a compile-time notice that calling finish() or
build() is largely unnecessary given that CookieBuilder implements
Into<Cookie>.
Cookie::named() was deprecated in favor of using Cookie::build() or
Cookie::from().
Cookie::named("foo") is equivalent to Cookie::from("foo").Cookie::build("foo") begins building a cookie equivalent to
Cookie::named("foo").Added Cookie::value_trimmed() and Cookie::name_value_trimmed().
These versions of Cookie::value() and Cookie::name_value(),
respectively, trim a matching pair of surrounding double quotes from the
cookie's value, if any are present.
String-like types, tuples of string-like types, and CookieBuilder
implement Into<Cookie>.
Implementations of Into<Cookie> for string-like types (&str, String,
Cow<str>), tuples of string-like types (name: string, value: string),
and CookieBuilder were added. The former implementations create a cookie
with a name corresponding to the string and an empty value. The tuple
implementation creates a cookie with the given name and value strings. The
CookieBuilder implementation returns the built cookie.
Key implements Debug.
To not leak sensitive information, the representation is simply "Key".
CookieBuilder implements Borrow{Mut}<Cookie>, As{Ref,Mut}<Cookie>,
Display.
Added CookieBuilder::inner{_mut}() to (mutably) borrow cookies being
built.
Added PrefixedJar and CookieJar::prefixed{_mut}(), which implement the
cookie prefixes HTTP draft.
Nothing published for this version
Cookie parsing no longer removes a . Domain prefix. Cookie::domain() now removes a . prefix before returning.
Cookie parsing no longer removes a . Domain prefix. Cookie::domain()
now removes a . prefix before returning.
As these changes are inverses, they are not likely observable. The change
only affects manually set domain values via the .domain() builder
method, the set_domain() setter method, or similar, which will now have a
prefix of . removed when returned by Cookie::domain(). This results in
more consistent treatment of Domain values.
Added Cookie::split_parse() and Cookie::split_parse_encoded() methods.
The methods split a ;-joined cookie string and parse/decode the split
values. They return a newly introduced iterator value of type SplitCookies
over the parse results.
base64 was updated to 0.21.### General Changes * base64 was updated to 0.20.
base64 was updated to 0.20.The ,, (, and ) are percent-encoded/decoded when encoding is used.
,, (, and ) are percent-encoded/decoded when encoding is used.aes-gcm dependency was updated to 0.10.The MSRV is now 1.53, up from 1.41 in 0.15.
1.53, up from 1.41 in 0.15.time has been updated to 0.3 and is reexported from the crate root.rust-crypto dependencies were updated to their latest versions.New release candidate version: 0.16.0-rc.1.
New release candidate version: 0.16.0-rc.1.
Nothing published for this version
A panic that could result from non-char boundary indexing was fixed.
0.14 were updated.Cookie::force_remove() takes &Cookie instead of Cookie.
Cookie::force_remove() takes &Cookie instead of Cookie.Cookie::{private{_mut}, signed{_mut}}).Cookie::encoded() returns a new Display struct.<= 99 are handled like Chrome: range 0..=68 maps to
2000..=2068, 69..=99 to 1969..=1999.Cookie::{set_}expires() operates on a new Expiration enum.Cookie::make_removal() to manually create expired cookies.Cookie::stripped() display variant to print only the name and
value of a cookie.Key implements a constant-time PartialEq.Key::master() to retrieve the full 512-bit master key.PrivateJar::decrypt() to manually decrypt an encrypted Cookie.SignedJar::verify() to manually verify a signed Cookie.Cookie::expires() returns an Option<Expiration> to allow distinguishing
between unset and None expirations.Cookie::expires_datetime() to retrieve the expiration as an
OffsetDateTime.Cookie::unset_expires() to unset expirations.Nothing published for this version
rust-crypto dependencies were updated to their latest versions.
rust-crypto dependencies were updated to their latest versions.Documentation now builds on the stable channel.
rust-crypto dependencies were updated to their latest versions.Updated base64 dependency to 0.12.
base64 dependency to 0.12.time dependency to correct version: 0.2.11.readme key to Cargo.toml, updated license field.The Key::from_master() method was deprecated in favor of the more aptly named Key::derive_from().
Key::from_master() method was deprecated in favor of the more aptly
named Key::derive_from().CookieJar::clear() method was removed.Key::from() to create a Key structure from a full-length key.signed and private features, respectively.key-expansion feature.ring is no longer a dependency: RustCrypto-based cryptography is used in
lieu of ring. Prior to their inclusion here, the hmac and hkdf crates
were audited.The time dependency was unpinned from 0.2.4, allowing any 0.2.x version of time where x >= 6.
time dependency was unpinned from 0.2.4, allowing any 0.2.x
version of time where x >= 6.The time dependency was pinned to 0.2.4 due to upstream breaking changes in 0.2.5.
time dependency was pinned to 0.2.4 due to upstream breaking changes
in 0.2.5.Added the CookieJar::reset_delta() method, which reverts all _delta_ changes to a CookieJar.
CookieJar::reset_delta() method, which reverts all delta
changes to a CookieJar.time was updated from 0.1 to 0.2.
time was updated from 0.1 to 0.2.ring was updated from 0.14 to 0.16.SameSite::None now writes SameSite=None to correspond with updated
SameSite draft. SameSite can be unset by passing None to
Cookie::set_same_site().CookieBuilder gained a lifetime: CookieBuilder<'c>.expires, max_age, path, and domain can be unset by passing None to
the respective Cookie::set_{field}() method.% character is now properly encoded and decoded.CookieBuilder allow non-static lifetimes.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →