NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1510 most downloaded on npm
<!-- automd:badges bundlejs packagephobia codecov -->
Last release 6 months ago
01 Apr 2026
Ships fairly regularly
a new release about every 9 months
Most releases are documented
notes for 12 of 14 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
14 releases · first in 2021
One column per quarter.
compare changes 📦 Build Avoid side-effects
serialize: Support custom stringify option for value coercion
stringify option for value coercion (6f659f8)compare changes 📦 Build Strip commands from mjs
cookie-es v3 brings full RFC 6265bis compliance with stricter validation, safer defaults, and improved APIs.
cookie-es v3 brings full RFC 6265bis compliance with stricter validation, safer defaults, and improved APIs.
Originally based on latest jshttp/cookie and nfriedly/set-cookie-parser.
serialize() accepts a SetCookie objectIn addition to serialize(name, val, opts?), you can now pass a single object:
// v2 (still works)
serialize("session", "abc", { httpOnly: true, secure: true });
// v3
serialize({ name: "session", value: "abc", httpOnly: true, secure: true });serialize()maxAge must be an integer, clamped to [0, 400 days]SameSite=None requires Secure — serialize({ name: "x", value: "y", sameSite: "none" }) now throwsPartitioned requires Secure — serialize({ name: "x", value: "y", partitioned: true }) now throws__Secure-/__Host- prefix cookies must have Secure; __Host- must also have Path=/ and no Domainfield-content pattern)parseSetCookie() returns undefined for invalid inputPreviously always returned an object:
// v2: { name: "", value: "" }
// v3: undefined
parseSetCookie("");parseSetCookie() enforces stricter limitsundefined if name+value exceeds 4096 octetsMax-Age to 400-day limitDomain valuesSameSite to "lax"__proto__, constructor, etc.)CookieSerializeOptions is now a compat aliasThe canonical type is CookieStringifyOptions. CookieSerializeOptions is CookieStringifyOptions & Omit<SetCookie, "name" | "value">.
stringifyCookie()The inverse of parse(): converts a Cookies object back into a Cookie header string:
const cookies = parse("session=abc; theme=dark");
// => { session: "abc", theme: "dark" }
stringifyCookie(cookies);
// => "session=abc; theme=dark"
stringifyCookie()vsserialize():serialize()builds aSet-Cookieheader for a single cookie with attributes (e.g.HttpOnly,Secure).stringifyCookie()is the roundtrip companion toparse()for theCookieheader.
parse() new optionsallowMultipleWhen enabled, duplicate cookie names return an array of values instead of only the first:
// v2: { id: "first" } (last duplicate wins)
// v3:
parse("id=first; id=second", { allowMultiple: true });
// => { id: ["first", "second"] }filterSkip specific keys during parsing:
parse("session=abc; theme=dark; debug=1", {
filter: (key) => key !== "debug",
});
// => { session: "abc", theme: "dark" }decode return type widenedCustom decode can now return undefined to exclude a cookie from the result:
parse("session=abc; token=secret", {
decode: (val) => (val === "secret" ? undefined : val),
});
// => { session: "abc", token: undefined }allowMultiple option (#55)parseCookie and serializeCookie aliases (f49c157)parseSetCookie implementations (a81865d)compare changes 🩹 Fixes parse: Use null proto object
compare changes 📦 Build ⚠️ ESM-only dist
🩹 Fixes parse: Use null proto object
Alexander Brandmüller eder.alexan@gmail.com
set-cookie: Compatible sameSite type with parse
sameSite type with parse (2d1c70e)Support filter option for key filtering
partitioned attribute of CookieSerializeOptions (#34)partitioned attribute of CookieSerializeOptions (#34)compare changes ### 🚀 Enhancements - Add partitioned option (#21) ### ❤️ Contributors - Alexander G - Pooya Parsa (@pi0)
partitioned option (#21)partitioned option (#21)Add explicit return types to exported functions
priority option (8b91b0c)priority option (e315835)types subpath export (#4)expires option should reject invalid dates (1a69d74)maxAge with null value (e4da31d).eslintcache (21a077b)Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →