NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #4319 most downloaded on crates.io
A library to work with Javascript Object Signing and Encryption(JOSE), including JSON Web Tokens (JWT), JSON Web Signature (JWS) and JSON Web Encryption (JWE).
Last release 6 months ago
05 Apr 2026
Ships unpredictably
gaps range from 1 weeks to 2.4 years
Nearly every release is documented
notes for 19 of 19 stable releases
1 version withdrawn
withdrawn after publishing
10 years old
23 releases · first in 2017
Bump Minimum Supported Rust Version (MSRV) to 1.66.0
Add Support for P-256 by @Wicpar in #310
Full Changelog: v0.6.0...v0.7.0
One column per quarter.
Fix build errors and bump MSRV by @lawliet89 in #308
jws::RegisteredHeader field web_keyOption<jwk::JWK<Empty>> instead of Option<String>. If you were not using JWKs,None will not breaking. If you were previously serializing yourjwk::JWK<Empty>. Please raiseJWKSet by @lawliet89 in #204Full Changelog: v0.5.0...v0.6.0
jws::RegisteredHeader field web_key
is now of type Option<jwk::JWK<Empty>> instead of Option<String>. If you were not using JWKs,
continue setting the value to None will not breaking. If you were previously serializing your
JWK as JSON strings, you will now have to deserialize them into jwk::JWK<Empty>. Please raise
issues if you encounter any bugs. [#189]jws::RegisteredHeader field web_key is now of type Option<jwk::JWK<Empty>> instead of Option<String> . If you were not using JWKs, continue setting th
jws::RegisteredHeader field web_keyOption<jwk::JWK<Empty>> instead of Option<String>. If you were not using JWKs,None will not breaking. If you were previously serializing yourjwk::JWK<Empty>. Please raiseThe only changes since v0.5.0-beta2 are dependencies upgrades and setting a higher MSRV.
The only changes since v0.5.0-beta2 are dependencies upgrades and setting a higher MSRV.
These are changes since v0.4.2.
MSRV is now Rust 1.41 due to changes in Cargo.lock format.
See announcement.
The jwk::AlgorithmParameters::OctetKey enum variant is now a newtype variant which takes a
jwk::OctetKeyParameters struct for its parameters. To migrate your existing code, you can do
the following
-jwk::AlgorithmParameters::OctetKey {
+jwk::AlgorithmParameters::OctetKey(jwk::OctetKeyParameters {
value: key,
key_type: Default::default(),
-}
+})(#125)
jws::Compact::decode_with_jwks now supports JWK without an alg specified. However, a new
parameter to specify an expected parameter had to be added to support this use case. This is to
mitigate against issues like
this.
Existing usage of JWK with the alg specified can simply add a None as the second parameter.
(#130)
Remove StringOrUri because it was hard to get the Uri type working properly. Replace all usage
of StringOrUri with Strings instead. (#131)
jwk::AlgorithmParameters::OctetKeyPair variant to support (de)serializing OKPkeypair as SecretThe changes below are since 0.5.0-beta1
The changes below are since 0.5.0-beta1
StringOrUri because it was hard to get the Uri type working properly. Replace all usageStringOrUri with Strings instead. (#131)keypair as SecretThe jwk::AlgorithmParameters::OctetKey enum variant is now a newtype variant which takes a jwk::OctetKeyParameters struct for its parameters. To migra
The jwk::AlgorithmParameters::OctetKey enum variant is now a newtype variant which takes a
jwk::OctetKeyParameters struct for its parameters. To migrate your existing code, you can do
the following
-jwk::AlgorithmParameters::OctetKey {
+jwk::AlgorithmParameters::OctetKey(jwk::OctetKeyParameters {
value: key,
key_type: Default::default(),
-}
+})(#125)
jws::Compact::decode_with_jwks now supports JWK without an alg specified. However, a new
parameter to specify an expected parameter had to be added to support this use case. This is to
mitigate against issues like
this.
Existing usage of JWK with the alg specified can simply add a None as the second parameter.
(#130)
jwk::AlgorithmParameters::OctetKeyPair variant to support (de)serializing OKPAdd jws::Compact::decode_with_jwks method to decode a JWT with JWKs
Fix documentation build on 1.40 Nightly
There are no new feature except for some breaking changes to correct some errors.
There are no new feature except for some breaking changes to correct some errors.
Octet MisspellingAll misspelling of octect have been corrected to octet. The following
types have been renamed and the old misspelt version is no longer available.
To migrate, you can simply do a case sensitive replace of Octect with Octet and
octect with octet in your code.
The following types have been renamed:
jwk::KeyType::Octect 🡒 jwk::KeyType::Octetjwk::KeyType::OctectKeyPair 🡒 jwk::KeyType::OctetKeyPairjwk::OctectKeyType 🡒 jwk::OctetKeyTypejwk::OctectKeyType::Octect 🡒 jwk::OctetKeyType::Octetjwk::AlgorithmParameters::OctectKey 🡒 jwk::AlgorithmParameters::OctetKeyThe following functions have been renamed:
jwk::JWK::new_octect_key 🡒 jwk::JWK::new_octet_keyjwk::JWK::octect_key 🡒 jwk::JWK::octet_keyjwk::AlgorithmParameters::octect_key 🡒 jwk::AlgorithmParameters::octet_keytrivially_copy_pass_by_ref lintThis release also fixes the
Clippy trivially_copy_pass_by_ref lint
by modifying function arguments that would have taken a reference of a 1 byte value that
implements Copy to take the value of itself. This mainly affects all struct methods
of the following types
There should be no need to modify your code for this because the types are Copy.
jwa::SignatureAlgorithmjwa::KeyManagementAlgorithmjwa::ContentEncryptionAlgorithmjwk::KeyTypeThere are no new features except for ring dependency changes.
There are no new features except for ring dependency changes.
Compact::to_string. Compact now implements Display which has a blanket
implementation of std::string::ToString. Use that instead. This should not break any
users because std::string::ToString is used by the std prelude.There are no new features or API changes except for ring dependency changes.
There are no new features or API changes except for ring dependency changes.
Minimum Rust 1.31 is needed for editions support on dependencies
Minimum Rust 1.31 is needed for editions support on dependencies
Minimum Rust 1.27.2 supported. Older versions might build, but this might not be supported.
There are breaking changes in this release:
There are breaking changes in this release:
ring was upgraded to 0.12. Until #619 lands,
this crate will now be incompatible with all other crates that uses a different version of ring.jwa::rng is no longer publicSignatureAlgorithm::verify now returns Result<(), Error> instead of Result<bool, Error>.lazy_static,
data-encoding.Other non-breaking changes include:
JWKSet to find key by Key IDjws::Compact to retrieve
parts without signature verification.There are no breaking changes in this release.
There are no breaking changes in this release.
Added a convenience validate_times function to jwe::Compact and jws::Compact that allows
quick temporal validation if their payloads are ClaimSets.
This release adds no new features and breaks no API. It simply bumps ring to 0.11.
This release adds no new features and breaks no API. It simply bumps ring to 0.11.
This release adds no new features and breaks no API. It simply bumps Chrono and Ring to their newest version.
This release adds no new features and breaks no API. It simply bumps Chrono and Ring to their newest version.
Update dependency to ring 0.9.4 so that different versions of ring can no longer be used in a Rust build.
Update dependency to ring 0.9.4 so that different versions of ring can no longer be used in a Rust build.
There are no new features or API change.
Minor bug fix release. Fixed incorrect ECDSA signature verification.
Minor bug fix release. Fixed incorrect ECDSA signature verification.
Thanks to @hobofan.
This is a major breaking release. Not all algorithms, verification, and features are supported yet.
This is a major breaking release. Not all algorithms, verification, and features are supported yet.
rustc_serialize with serdebiscuit::Empty convenice empty struct that users can plug into type parameters when they do
not need them, such as the type parameter of custom headers.SingleOrMultiple and StringOrUri enums to better represent the types of values that the JOSE
RFCs allow.biscuit::JWT is no longer a struct. It is now a type alias for jws::Compact, which according
to the RFC, is the compact serialization of a JSON Web Signature (JWS).biscuit::Algorithm to biscuit::jwa::SignatureAlgorithm to better reflect its use.biscuit have been
changed, added, or removed.This is an initial release after forking from Version 1.1.6 of `Keats/rust-jwt`.
This is an initial release after forking from Version 1.1.6 of Keats/rust-jwt.
ring)Your coding agent can read these notes before it upgrades. Set up the MCP server →