Very cool, I'll have to take a look at the gorilla/sessions work.
As for the cookie mode, I'd make encrypt + HMAC [along with the nonce + timestamping & expire goodies] the default. There are a lot of reasons you shouldn't show a user what's in their 'internal state' - and users of your library may not understand that.
If you're HMAC'n you're already using a secret key, so - no great shakes to default to the encrypted mode.