On this page
Overview
iron-session is a stateless cookie-based session library for JavaScript. It stores session data in signed and encrypted cookies, allowing Next.js App Router, Route Handlers, Server Actions, Proxy, and other server runtimes to manage sessions without a separate Redis or session database.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Keep sessions in encrypted cookies without a server-side session store
getIronSession unseals session data from cookies and session.save() writes the updated sealed value. No network round trip to a session store is required. Passwords must be at least 32 characters and multiple keyed passwords can be used for rotation.
Sources: [1]
Use one session API across Next.js App Router, Route Handlers, and Proxy
Next.js cookies() can be passed directly, while nextProxyCookies, webCookies, and nodeCookies adapters cover Proxy, web-standard runtimes, and Node/Express-style request handling.
Sources: [1]
Best fit
Fits Next.js applications that keep session payloads small and want no extra session service
A common fit is storing a user ID or small authentication state in the cookie and loading larger data from a database. Browsers reject cookies above 4096 bytes, and the README recommends planning for roughly 3KB of actual session data.
Sources: [1]
Before adoption
Version 9 requires Node 22.13 or later and is ESM-only
Version 9 requires Node 22.13+, uses ESM only, rejects Date objects in session data in favor of timestamps, and types readable session properties as Partial<T> because a session may be empty.
Combine stateless sessions with database checks when immediate revocation matters
Because the server does not keep session state by default, instantly invalidating every session for a specific user is not inherent to the model. Sensitive requests should re-check user status and permissions in a database when immediate revocation is required.
Sources: [1]
Official sources
- [1]iron-session v9.0.1 README(2026-10-06)
- [2]iron-session v9 migration guide(2026-10-06)
- [3]iron-session v9.0.1 release(2026-10-06)
Supplemental curator note
It fits Next.js applications that want small authentication state without an extra session store. Review cookie size, password rotation, immediate-revocation requirements, and the v9 Node/ESM baseline.
Try it in 3 steps
- 1
Get the source
git clone --depth 1 https://github.com/vvo/iron-session.git - 2
Enter the repository
cd iron-session - 3
Check the official steps
Continue with the commands in the README Installation, Quick Start, or Getting Started section.
find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Growth
Growth trends · Last 30 days
4,141 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 1
- Open PRs
- 0
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- nextjs
- authentication
- session
- stateless
- cookies
- expressjs
- nodejs
- serverless
- Stars
- 4,141
- Forks
- 254
- Watchers
- 9
- Open issues
- 1
- Contributors
- 46
- Owner type
- User
- Primary language
- TypeScript
- License
- MIT
- Repository last updated
- Sep 23, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Marked37,224 Stars
2 shared tag(s) · 1 shared category(s) · Same language
convert Markdown to HTML in Node.js, browsers, and the CLI and extend parsing through extensions
TypeScript - date-fns36,649 Stars
2 shared tag(s) · 1 shared category(s) · Same language
format, compare, and calculate JavaScript dates with small pure functions
TypeScript - Auth.js28,367 Stars
5 shared tag(s) · 1 shared category(s) · Same language
Compose OAuth/OIDC, passwordless, WebAuthn, and stateless or database-backed sessions from packages built around standard Web APIs
TypeScript - jose7,815 Stars
4 shared tag(s) · 2 shared category(s) · Same language
handle JWT, JWS, JWE, JWK, and JWKS with a zero-dependency Web-standard JOSE library
TypeScript - Playwright97,099 Stars
3 shared tag(s) · 1 shared category(s) · Same language
Drive Chromium, Firefox, and WebKit through one API and test runner for E2E, scripting, and agent browser automation
TypeScript - Trigger.dev16,474 Stars
3 shared tag(s) · 1 shared category(s) · Same language
run long tasks, retries, queues, and schedules durably from TypeScript code
TypeScript
Report incorrect information
Tell us if any listing information is incorrect or outdated.