Cookies
Azion Lib functions of the azion package that read cookies from an HTTP request and set cookies on an HTTP response.
The azion/cookies module is the Azion Lib library for HTTP cookies. Its two functions read cookies from the Cookie header of a Request and set a cookie on a Response through the Set-Cookie header. They make no API calls, need no token, and return their result directly.
Install the package:
The azion package receives bug fixes only, and its maintenance ends in December 2026.
The functions take the standard Request and Response objects. They run in Node.js, and they run inside a function served locally with azion dev. The getCookie and setCookie samples are TypeScript ES modules run in Node.js, and they import types with import type. Both functions are also properties of the default export, cookies.
getCookie
Reads one cookie by its name, or every cookie of the request.
| Parameter | Type | Required | Description |
|---|---|---|---|
req | Request | Yes | The request that carries the Cookie header. |
key | string | No | The name of the cookie to read. Without it, the function returns every cookie. Required when you pass prefixOptions. |
prefixOptions | CookiePrefix | No | The name prefix of the cookie. With host, the function reads __Host-<key>; with secure, it reads __Secure-<key>. |
Returns the value of the cookie as a string when you pass key, or undefined when the request has no cookie with that name. Without key, it returns a Record<string, string> of every cookie, with each name as the request sends it, prefix included.
This sample builds a request with three cookies and reads one cookie, every cookie, a __Host- cookie, and a cookie that is not there:
Output:
setCookie
Sets a cookie on a response.
| Parameter | Type | Required | Description |
|---|---|---|---|
res | Response | Yes | The response to set the cookie on. |
key | string | Yes | The name of the cookie. |
value | string | Yes | The value of the cookie. |
options | CookieOptions | No | The attributes of the cookie. |
Returns the Response with a Set-Cookie header that holds the cookie and its attributes. Return this response from your handler, so the client receives the cookie.
With prefix: 'host', set path: '/' too. Without it, setCookie throws an error with the message path option must be set to / when using host prefix.
This sample sets a cookie with five attributes, then a cookie with the host prefix, and prints each Set-Cookie header:
Output:
Read and set cookies in a function
This function reads the theme cookie, falls back to light when the request has none, and sets a visited cookie on the response:
Served locally with azion dev, a request with a Cookie header and a request without one return:
Types
The module exports these types. Import them with import type.
CookieOptions
The attributes setCookie writes on the cookie.
| Property | Type | Required | Description |
|---|---|---|---|
domain | string | No | The domain the cookie is valid for. |
expires | Date | No | The expiration date of the cookie. |
httpOnly | boolean | No | With true, adds the HttpOnly attribute, which keeps the cookie out of reach of JavaScript in the browser through document.cookie. |
maxAge | number | No | The maximum age of the cookie, in seconds. Written as Max-Age. |
path | string | No | The path the client sends the cookie for. Must be / with prefix: 'host'. |
sameSite | 'Lax' | 'None' | 'Strict' | No | How the client sends the cookie with cross-site requests. |
secure | boolean | No | With true, adds the Secure attribute, so the client sends the cookie over HTTPS only. |
prefix | CookiePrefix | No | The name prefix. With host, the cookie name starts with __Host-. |
partitioned | boolean | No | With true, adds the Partitioned attribute. |
CookiePrefix
The name prefix that getCookie reads and setCookie writes.