OSS TanbouSign in with GitHub

store session data in signed and encrypted cookies for stateless server-side sessions in Next.js

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
4,141
Primary language
TypeScript
License
MIT
Repository last updated
Sep 23, 2026
On this page

Overview

iron-session is a stateless cookie-based session library for JavaScript. It stores session data in signed and encrypted cookies, allowing Next.js App Router, Route Handlers, Server Actions, Proxy, and other server runtimes to manage sessions without a separate Redis or session database.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Keep sessions in encrypted cookies without a server-side session store

getIronSession unseals session data from cookies and session.save() writes the updated sealed value. No network round trip to a session store is required. Passwords must be at least 32 characters and multiple keyed passwords can be used for rotation.

Sources: [1]

Use one session API across Next.js App Router, Route Handlers, and Proxy

Next.js cookies() can be passed directly, while nextProxyCookies, webCookies, and nodeCookies adapters cover Proxy, web-standard runtimes, and Node/Express-style request handling.

Sources: [1]

Best fit

Fits Next.js applications that keep session payloads small and want no extra session service

A common fit is storing a user ID or small authentication state in the cookie and loading larger data from a database. Browsers reject cookies above 4096 bytes, and the README recommends planning for roughly 3KB of actual session data.

Sources: [1]

Before adoption

Version 9 requires Node 22.13 or later and is ESM-only

Version 9 requires Node 22.13+, uses ESM only, rejects Date objects in session data in favor of timestamps, and types readable session properties as Partial<T> because a session may be empty.

Sources: [1][2]

Combine stateless sessions with database checks when immediate revocation matters

Because the server does not keep session state by default, instantly invalidating every session for a specific user is not inherent to the model. Sensitive requests should re-check user status and permissions in a database when immediate revocation is required.

Sources: [1]

Official sources

  1. [1]iron-session v9.0.1 README(2026-10-06)
  2. [2]iron-session v9 migration guide(2026-10-06)
  3. [3]iron-session v9.0.1 release(2026-10-06)
Supplemental curator note

It fits Next.js applications that want small authentication state without an extra session store. Review cookie size, password rotation, immediate-revocation requirements, and the v9 Node/ESM baseline.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/vvo/iron-session.git
  2. 2

    Enter the repository

    cd iron-session
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

4,141 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
1
Open PRs
0

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • nextjs
  • authentication
  • session
  • stateless
  • cookies
  • expressjs
  • nodejs
  • serverless
Stars
4,141
Forks
254
Watchers
9
Open issues
1
Contributors
46
Owner type
User
Primary language
TypeScript
License
MIT
Repository last updated
Sep 23, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?