Setting and Reading Cookies

A cookie is a name/value pair the server sends in a Set-Cookie response header and the browser replays in a Cookie request header. Express 24,430 gives you res.cookie(name, value, options); for the read side, cookie-parser 2,030 (1.4.7) parses the incoming header into the plain object req.cookies.

Writing, reading and clearing cookiesJavaScript
app.use(cookieParser('s3cr3t-signing-key'));
app.get('/set', (req, res) => {
  res.cookie('theme', 'dark', { maxAge: 900000, sameSite: 'lax' });
  res.cookie('cart', { items: 3, total: 41.5 });     // objects are JSON-encoded
  res.send('cookies set');
});
app.get('/read', (req, res) => res.json({ cookies: req.cookies }));
app.get('/clear', (req, res) => {
  res.clearCookie('theme', { sameSite: 'lax' });     // options must match the original
  res.send('cleared');
});
Output
$ curl -s -i http://localhost:3101/set
Set-Cookie: theme=dark; Max-Age=900; Path=/; Expires=Thu, 17 Sep 2026 17:39:07 GMT;
  SameSite=Lax
Set-Cookie: cart=j%3A%7B%22items%22%3A3%2C%22total%22%3A41.5%7D; Path=/
$ curl -s -b jar.txt .../read  ->  {"cookies":{"theme":"dark","cart":{"items":3,"total":41.5}}}
$ curl -s -i .../clear | grep -i set-cookie
Set-Cookie: theme=; Path=/; Expires=Thu, 01 Jan 1970 00:00:00 GMT; SameSite=Lax

Each res.cookie call appends one header, so a response can carry several. You pass maxAge in milliseconds; Express emits Max-Age in seconds plus an Expires date for old clients. The cart value shows cookie-parser's object convention, j: followed by JSON — a convenience, not a standard. Deleting a cookie means overwriting it with an expiry in the past, as the third response does.

Keep cookies small: browsers guarantee only 4096 bytes each, and every cookie in scope rides along on every matching request, images included. Anything larger than an identifier belongs in a session store (express-session).