# universal-cookie

> Universal cookies for JavaScript

Latest version **8.1.2** (published 2026-04-29) · MIT license · 0 weekly downloads

## Install

```sh
npm install universal-cookie
pnpm add universal-cookie
yarn add universal-cookie
bun add universal-cookie
```

## Health

**Score 60/100 (C)** — status: active.

Positive: has types; esm support; no vulnerabilities; has provenance.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 8.1.2 |
| Published | 2026-04-29 |
| First published | 2017-04-16 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Dependencies | 1 |
| Unpacked size | 62.2 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Provenance | attested (GitHub Actions) |
| GitHub stars | 215 |
| Author | Benoit Tremblay |
| Maintainers | exon |
| Keywords | universal, isomophic, cookie |

## Links

- npm: https://www.npmjs.com/package/universal-cookie
- Repository: https://github.com/ItsBenCodes/cookies
- Homepage: https://github.com/ItsBenCodes/cookies/tree/main/packages/universal-cookie#readme
- Issues: https://github.com/ItsBenCodes/cookies/issues
- npm.io page: https://npm.io/package/universal-cookie

## Dependencies (1)

- [cookie](https://npm.io/package/cookie.md) ^1.1.1

## Recent versions

- 8.1.2 (latest) — 2026-04-29
- 8.1.1 — 2026-04-29
- 8.1.0 — 2026-03-30
- 8.0.1 — 2025-03-18
- 8.0.0 — 2025-03-14
- 7.2.2 — 2024-10-29
- 7.2.1 — 2024-10-09
- 7.2.0 — 2024-07-21
- 7.1.4 — 2024-04-01
- 7.1.3 — 2024-04-01
- 7.1.2 — 2024-03-31
- 7.1.1 — 2024-03-31
- 7.1.0 — 2024-02-22
- 7.0.2 — 2024-01-27
- 7.0.1 — 2024-01-06
- … 34 more at https://npm.io/package/universal-cookie/versions

## README

<h3 align="center">
  universal-cookie
</h3>

<p align="center">
  Universal cookies for JavaScript<br />
  <a href="https://badge.fury.io/js/universal-cookie"><img src="https://badge.fury.io/js/universal-cookie.svg" /></a>
  <img src="https://github.com/github/docs/actions/workflows/test.yml/badge.svg" />
</p>

## Integrations

- [`react-cookie`](https://www.npmjs.com/package/react-cookie) - Universal cookies for React
- [`universal-cookie-express`](https://www.npmjs.com/package/universal-cookie-express) - Hook cookies get/set on Express for server-rendering

## Getting started

`npm install universal-cookie`

or in the browser (global variable `UniversalCookie`):

```html
<script
  crossorigin
  src="https://unpkg.com/universal-cookie@7/umd/universalCookie.min.js"
></script>
```

## API - Cookies class

### `constructor([cookieHeader], [defaultSetOptions])`

Create a cookies context

- cookieHeader (string|object): specify the cookie header or object
- defaultSetOptions (object): specify the default options when setting cookies
  - path (string): cookie path, use `/` as the path if you want your cookie to be accessible on all pages
  - expires (Date): absolute expiration date for the cookie
  - maxAge (number): relative max age of the cookie from when the client receives it in seconds
  - domain (string): domain for the cookie (sub.domain.com or .allsubdomains.com)
  - secure (boolean): Is only accessible through HTTPS?
  - httpOnly (boolean): Is only the server can access the cookie? **Note: You cannot get or set httpOnly cookies from the browser, only the server.**
  - sameSite (boolean|none|lax|strict): Strict or Lax enforcement
  - partitioned (boolean): Indicates that the cookie should be stored using partitioned storage

### `get(name, [options])`

Get a cookie value

- name (string): cookie name
- options (object):
  - doNotParse (boolean): do not convert the cookie into an object no matter what

### `getAll([options])`

Get all cookies

- options (object):
  - doNotParse (boolean): do not convert the cookie into an object no matter what

### `set(name, value, [options])`

Set a cookie value

- name (string): cookie name
- value (string|object): save the value and stringify the object if needed
- options (object): Support all the cookie options from RFC 6265
  - path (string): cookie path, use `/` as the path if you want your cookie to be accessible on all pages
  - expires (Date): absolute expiration date for the cookie
  - maxAge (number): relative max age of the cookie from when the client receives it in seconds
  - domain (string): domain for the cookie (sub.domain.com or .allsubdomains.com)
  - secure (boolean): Is only accessible through HTTPS?
  - httpOnly (boolean): Is only the server can access the cookie? **Note: You cannot get or set httpOnly cookies from the browser, only the server.**
  - sameSite (boolean|none|lax|strict): Strict or Lax enforcement
  - partitioned (boolean): Indicates that the cookie should be stored using partitioned storage

### `remove(name, [options])`

Remove a cookie

- name (string): cookie name
- options (object): Support all the cookie options from RFC 6265
  - path (string): cookie path, use `/` as the path if you want your cookie to be accessible on all pages
  - expires (Date): absolute expiration date for the cookie
  - maxAge (number): relative max age of the cookie from when the client receives it in seconds
  - domain (string): domain for the cookie (sub.domain.com or .allsubdomains.com)
  - secure (boolean): Is only accessible through HTTPS?
  - httpOnly (boolean): Is only the server can access the cookie? **Note: You cannot get or set httpOnly cookies from the browser, only the server.**
  - sameSite (boolean|none|lax|strict): Strict or Lax enforcement
  - partitioned (boolean): Indicates that the cookie should be stored using partitioned storage

### `addChangeListener(callback)`

Add a listener to when a cookie is set or removed.

- callback (function): Call that will be called with the first argument containing `name`, `value` and `options` of the changed cookie.

### `removeChangeListener(callback)`

Remove a listener from the change callback.

### `removeAllChangeListeners()`

Remove all change listeners that were previously added with `addChangeListener()`.

### `update()`

Read back the cookies from the browser and triggers the change listeners. This should normally not be necessary because this library detects cookie changes automatically.

## Browser Example

```js
import Cookies from 'universal-cookie';

const cookies = new Cookies(null, { path: '/' });

cookies.set('myCat', 'Pacman');
console.log(cookies.get('myCat')); // Pacman
```

## Server Example

```js
import Cookies from 'universal-cookie';

const cookies = new Cookies(req.headers.cookie, { path: '/' });

console.log(cookies.get('myCat')); // Pacman or undefined if not set yet
```

---
_Source: https://npm.io/package/universal-cookie · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
