NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #89 most downloaded on npm
HTTP server cookie parsing and serialization
Last release 3 months ago
30 Jun 2026
Release timing varies
gaps range from 8 days to 3.0 years
Most releases are documented
notes for 23 of 35 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
35 releases · first in 2012
Small performance improvement by incrementing = index while parsing set-cookie
Improved:
= index while parsing set-cookie (#280)Important: This release moves the package to ESM only. In node 22+ you can require(esm) , and older node versions are not supported.
Important: This release moves the package to ESM only. In node 22+ you can require(esm), and older node versions are not supported.
Changed
parse and stringify methods have been renamed: parseCookie and stringifySetCookiestringifySetCookie only supports object mode (e.g. { name: "", value: "" })Improvements
encode to empty cookie values (#277)Fixed
One column per quarter.
Overwrite value in passed in options ( #253 ) c66147c
Add stringifyCookie and parseSetCookie methods ( #244 , #214 )
Loosen cookie name/value validation
Fixed
options.priority used incorrect fallback (#207) by @jonchurchAdded
Allow case insensitive options ( #194 ) 3bed080
Use modern JS features, ship TypeScript definition ( #175 ) 1cc64ff
Breaking changes
__esModule marker, imports need to use import { parse, serialize } or import * as cookieparse return valuestrict and priority to match the lower case strings (i.e. low, not LOW or Low)maxAge to be an integer using Number.isInteger checkdecode option (i.e. error handling and quote parsing is defined by decode)
Other
hasOwnProperty, use undefined check for performance (#183) 8f3ee9e @gurgundayFix object assignment of hasOwnProperty ( #177 ) bc38ffd
Although not permitted in the spec, some users expect this to work and user agents ignore the leading dot according to spec
Fixed
serialize without options, use obj.hasOwnProperty when parsing (#172)https://github.com/jshttp/cookie/compare/v0.7.0...v0.7.1
Fixed
perf: parse cookies ~10% faster (#144 by @kurtextrem and #170)
main to package.json for rspack (#166 by @proudparrot2)https://github.com/jshttp/cookie/compare/v0.6.0...v0.7.0
main to package.json for rspack (#166 by @proudparrot2)Nothing published for this version
Fix expires option to reject invalid dates
priority option
expires option to reject invalid datespref: read value only when assigning in parse
Fix maxAge option to reject invalid values
maxAge option to reject invalid valuesNothing published for this version
Fix sameSite: true to work with draft-7 clients
sameSite: true to work with draft-7 clients
true now sends SameSite=Strict instead of SameSiteReplaces firstPartyOnly option, never implemented by browsers
sameSite option
firstPartyOnly option, never implemented by browsersencode is not a functionexpires is not a Dateperf: use string concatination for serialization
Fix cookie Max-Age to never be a floating point number
Max-Age to never be a floating point numberFix regression when setting empty cookie value
Throw on invalid values provided to serialize
serialize
Throw better error for invalid argument to parse
firstPartyOnly optionFix regression when setting empty cookie value
Throw better error for invalid argument to parse
serialize
Reduce the scope of try-catch deopt
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →