the maxAge option is misleading. It should translate to the max-age cookie directive, not expires with Date.now() base.
Date.now causes issues when maxAge is low (a few hours), since it uses the server date, and the client date may be different due to timezones.