NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1605 most downloaded on npm
A simple, lightweight JavaScript API for handling cookies
Last release 4 months ago
29 May 2026
Ships unpredictably
gaps range from 9 days to 3.1 years
Nearly every release is documented
notes for 20 of 20 stable releases
3 versions withdrawn
withdrawn after publishing
11 years old
35 releases · first in 2015
Restore ES5 compatibility, inadvertently broken in 3.0.7 - #959
Prevent cookie attribute injection: CVE-2026-46625
Partitioned attribute to readme (b994768)get('name') + get() (1953d30)One column per quarter.
Nothing published for this version
Remove npm version restriction in package.json - #818
Publish to npmjs.com with package provenance
Nothing published for this version
Nothing published for this version
Make package.json accessible in export - #727
Removed defaults in favor of a builder: now to supply an api instance with particular predefined (cookie) attributes there's Cookies.withAttributes()
defaults in favor of a builder: now to supply an api instance with particular predefined (cookie) attributes there's Cookies.withAttributes(), e.g.:const api = Cookies.withAttributes({
path: '/',
secure: true
})
api.set('key', 'value') // writes cookie with path: '/' and secure: true...attributes property; it's an immutable object and unlike defaults cannot be changed to configure the api.Cookies.converter, which allows for implementing self-contained custom converters providing the same behavior:const customReadConverter = (value, name) => {
if (name === 'special') {
return unescape(value)
}
return Cookies.converter.read(value)
}withConverter() no longer accepts a function as argument to be turned into a read converter. It is now required to always pass an object with the explicit type(s) of converter(s):const api = Cookies.withConverter({
read: (value, name) => unescape(value)
})converter property; it's an immutable object and cannot be changed to configure the api.module field in package.json points to an ES module variant of the library.browser field instead of main in package.json (for the UMD variant of the library).getJSON() and automatic stringifying in set(): use Cookies.set('foo', JSON.stringify({ ... })) and JSON.parse(Cookies.get('foo')) instead.Reverted changes introduced in rc2 , which caused a mayor breaking change in the case of requesting the library via jsdelivr CDN with a particular fil…
Reverted changes introduced in rc2, which caused a mayor breaking change in the case of requesting the library via jsdelivr CDN with a particular file name. This breaking change was not intentional.
The problem was that we've been advertising the following link in the readme on the master branch:
https://cdn.jsdelivr.net/npm/js-cookie@rc/dist/js.cookie.min.js
while the respective change had changed that file name in the distribution to js.cookie.umd.min.js.
Nonetheless, we advise to always use the latest stable version in production environments.
Fixed paths in exports field in package.json - #695
exports field in package.json - #695Improved module setup in package.json to account for older Node.js versions - #666
Fixed regression where in Safari cookie values containing non-ASCII characters were no longer written correctly - #623
Nothing published for this version
Revisited encoding/decoding implementation: we start to only encode characters in the cookie name and value that are strictly necessary (";" and "=" i
Fixed importing ES module when not using a bundler - #583
attributes + converter properties on api instance immutable againFixed noConflict() no longer being present; as a result the api instance is no longer immutable again - #580
noConflict() no longer being present; as a result the api instance is no longer immutable again - #580Removed defaults in favor of a builder: now to supply an api instance with particular predefined (cookie) attributes there's Cookies.withAttributes(),
defaults in favor of a builder: now to supply an api instance with particular predefined (cookie) attributes there's Cookies.withAttributes(), e.g.:const api = Cookies.withAttributes({
path: '/',
secure: true
})
api.set('key', 'value') // writes cookie with path: '/' and secure: true...
attributes property; it's an immutable object and unlike defaults cannot be changed to configure the api.Cookies.converter, which allows for implementing self-contained custom converters providing the same behavior:const customReadConverter = (value, name) => {
if (name === 'special') {
return unescape(value)
}
return Cookies.converter.read(value)
}
withConverter() no longer accepts a function as argument to be turned into a read converter. It is now required to always pass an object with the explicit type(s) of converter(s):const api = Cookies.withConverter({
read: (value, name) => unescape(value)
})
converter property; it's an immutable object and cannot be changed to configure the api.Started providing library as ES module, in addition to UMD module. The module field in package.json points to an ES module variant of the library.
module field in package.json points to an ES module variant of the library.browser field instead of main in package.json (for the UMD variant of the library).getJSON(): use Cookies.set('foo', JSON.stringify({ ... })) and JSON.parse(Cookies.get('foo')) instead.* #400: Prevent XSS in the cookie attributes * #350: Document npm package manager usage
https://github.com/js-cookie/js-cookie/pull/221: Only include files in src/ when building the npm package.
src/ when building the npm package.getJSON() does not work on cookie with escaped quoteshttps://github.com/js-cookie/js-cookie/issues/321: Create a security disclosure e-mail
- #205: Add expired cookie detail to docs - #215: Clarify the interoperability of default encoding - #207: Add support for uglifyJS 'unsafe' option -
* #189, #180, #177: Minor documentation improvements * #204: Fix the docs, because It is not necessary the secure attribute when removing a cookie * #
secure attribute when removing a cookie* #164: The library should not throw an error if the methods are used in node * #145: Should not create a cookie if the .set() API is used incorrectly
.set() API is used incorrectlyhttps://github.com/js-cookie/js-cookie/commit/591e663c85f4c6edcc4a283eba67f0e8067fdf81: Add examples do handle server-side incompatibilities using the
Nothing published for this version
- #68: The JSON-js polyfill requirement in the README should not include IE8 - #91: Enhance the docs to clarify the browser behavior for the domain at
domain attributebower.json in order to release with webjars- #62: Fix a Malformed URI error for getting a cookie when an unrelated one was encoded using escape - #64: Fix the documentation, the converter is no
Malformed URI error for getting a cookie when an unrelated one was encoded using escape.remove() method- #54: Fixed an issue with expires attribute set to false
expires attribute set to falseFix npm publication. Only tagged releases should appear as published, the temporary version 2.1.0-pre should not.
2.1.0-pre should not.js-cookie respects the RFC 6265 proposed standard, which was proposed in April 2011 and specifies how all modern browsers currently interpret cookie h
js-cookie respects the RFC 6265 proposed standard, which was proposed in April 2011 and specifies how all modern browsers currently interpret cookie handling.
js-cookie v2 is not backwards compatible with jquery-cookie or js-cookie v1.
Below is the list of everything that was changed, along with the new equivalent feature (if applicable).
$) is removedjQuery is not necessary anymore. Below is the list of old methods and their new equivalent.
$.cookie('name', 'value') -> Cookies.set('name', 'value')
$.cookie('name') -> Cookies.get('name')
$.removeCookie('name') -> Cookies.remove('name')
$.cookie() -> Cookies.get()
For more information, check the discussion.
raw config is removed, use convertersjs-cookie encodes the cookie name/value automatically using UTF-8 percent encoding for each character that is not allowed according to the RFC 6265.
You can simulate the same behavior of raw = true by instantiating a converter that returns the original value to bypass the default decoding:
var RawCookies = Cookies.withConverter(function(value) {
return value;
});
RawCookies.get('name'); // The returned value was not decoded
Note: simply bypassing the encoding is a bad practice, if your cookie contains an invalid character, it will NOT work in some browsers like Safari or IE.
For more information, check the converters docs.
json config is removed, use Cookies.getJSON()If you pass a Plain Object Literal or Array to the value, js-cookie will stringify it. To retrieve the parsed value, just call the cookie using Cookies.getJSON('name').
For more information, check the docs.
path now is default to the whole site '/'What was known as "options" is now documented as "attributes". In the last versions, the default value for the path option was delegated to the browser defaults (valid to the path of the current page where each cookie is being set). Now, the default path attribute is the whole site /.
To remove, set or declare defaults to the path of the current page, you just need to declare it as empty:
Cookies.defaults.path = '';
Deleting the property will fallback to path: / internally:
delete Cookies.defaults.path;
For more information, check the details.
Previously, $.removeCookie() and Cookies.remove() returned either true or false based on whether the cookie was successful deleted or not. Now its returned value should be considered undefined and not be relied upon.
For more information, check the details.
Nothing published for this version
- #24: Add the .noConflict() method to the Cookies namespace
.noConflict() method to the Cookies namespacecarhartl/jquery-cookie#349: Make jquery as an optional dependency. $.cookie is deprecated.
$.cookie is deprecated.Your coding agent can read these notes before it upgrades. Set up the MCP server →