NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #548 most downloaded on crates.io
Create and decode JWTs in a strongly typed way.
Last release 21 days ago
16 Sep 2026
Release timing varies
gaps range from 3 weeks to 11 months
Most releases are documented
notes for 33 of 46 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
59 releases · first in 2015
Add dangerous::insecure_decode_claims
dangerous::insecure_decode_claimsAdd conversions between Algorithm and KeyAlgorithm
Algorithm and KeyAlgorithmDecodingKeys, creation from EncodingKey and DecodingKey now supports Ed25519 as wellAlgorithm, KeyAlgorithm, EllipticCurve and ThumbprintHash are now non_exhaustiveJwk.thumbprint now returns a Result<_>Header.extras is now a struct that allows for deserialization to any TValidation.insecure_disable_signature_validation has been removed, use dangerous::insecure_decode insteadEncodingKey.inner has been renamed to as_bytes, try_get_hmac_secret has been removedDecodingKey.as_bytes and try_get_hmac_secret have been removed, use try_get_as_bytes insteadCryptoProvidersJwkUtils has been renamed to KeyUtils
compute_digest now returns a Result<_>extract_rsa_public_key_components has been renamed to rsa_pub_components_from_private_keyrsa_pub_components_from_public_key has been addedextract_ec_public_key_coordinates has been renamed to ec_pub_components_from_private_keyed_pub_components_from_private_key has been addedOne column per quarter.
Fix incorrect encoding for Ed25519 JWK thumbprints
Algorithm.family public and add Validation.new_for_familyEncodingKey and DecodingKey are now partially zeroized on drop (the intermediate PemEncodedKey isn't so far)Export everything needed to define your own CryptoProvider
Remove Clone bound from decode functions
Clone bound from decode functionsImplement TryFrom &Jwk for DecodingKey
dangerous::insecure_decodecargo fmt post edition bump
cargo fmt post edition bump
aws_lc_rs and rust_cryptoClone bound to decode- Update base64
Add Validation.reject_tokens_expiring_in_less_than, the opposite of leeway
Validation.reject_tokens_expiring_in_less_than, the opposite of leewayAdd an option to not validate aud in the Validation struct
aud in the Validation structSupports deserialization of unsupported algorithms for JWKs
Rejects JWTs containing audiences when the Validation doesn't contain any
Implement Clone for TokenData if T impls Clone
Can now use PEM certificates if you have the use_pem feature enabled
use_pem feature enabledFix invalid field name on OctetKeyParameters
Make optional fields in the spec really optional
Hash for Header- Fix documentation of leeway
Remove deprecated dangerous_unsafe_decode
sign/verify now takes a &[u8] instead of &str to be more flexibleDecodingKey now own its datadangerous_unsafe_decodeValidation::iss is now a HashSet instead of a single valuedecode will now error if Validation::algorithms is emptyexamples/auth0.rs for an exampledecode_* functions in favour of using the Validation structexp and nbf, yes it's in the spec... floats will be rounded and converted to u64Validation::require_spec_claims to validate presence of the spec claimsuse_pem that can be disabled to avoid 2 dependenciesNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add dangerous_insecure_decode to replace dangerous_unsafe_decode, which is now deprecated
dangerous_insecure_decode to replace dangerous_unsafe_decode, which is now deprecateddangerous_insecure_decode_with_validationDerive Hash for Header and Algorithm
Hash for Header and Algorithm- Update dependencies
Add into_static to DecodingKey for easier re-use
into_static to DecodingKey for easier re-useOption<HashSet<String>>. Audience
validation now tests for "any-of-these" audience membership.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix Algorithm mapping in FromStr for RSA
Remove iat check to match the JWT spec
iat check to match the JWT specAdd implementation of FromStr for Algorithm
Change error handling to be based on simple struct/enum rather than error-chain
iat and nbf anymoreAdd method to decode a token without signature verification
Make it mandatory to specify the algorithm in decode
decodeRemove validate_signature from Validation, use decode_header instead if you don't know the alg used
validate_signature from Validation, use decode_header instead if you don't know the alg usedtyp optional in header, some providers apparently don't use itleeway being in seconds and not millisecondsdecode_header to only decode the header: replaces the use case of validate_signature- Make TokenData public
TokenData public- Update ring & chrono
- Update ring
Use Serde instead of rustc_serialize
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →