NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #3398 most downloaded on crates.io
PASETO: Platform-Agnostic Security Tokens (in Rust)
Last release 1 months ago
30 Aug 2026
Ships fairly regularly
a new release about every 3 months
Nearly every release is documented
notes for 28 of 28 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
35 releases · first in 2020
One column per quarter.
__Date:__ August 30, 2026. - Bump orion to 0.18.0
Date: August 30, 2026.
orion to 0.18.0(BREAKING) Remove rand_core from dependencies.
Date: July 23, 2026.
rand_core from dependencies.ed25519-compact from 2.0.2 to 2.3.1.zeroize from 1.4.1 to 1.9.subtle from 2.4.1 to 2.6.1.p384 from 0.13.0 to 0.14.0.sha2 from 0.10.2 to 0.11.0.S on signing operation in V3. This achieves higher compatability with reference PHP implementation, but does not change spec-adherence.__Date:__ February 23, 2026. - Bump MSRV to 1.88. - Bump getrandom to 0.4.
Date: February 23, 2026.
1.88.getrandom to 0.4.Omit fractional seconds in DateTime claims on creation (#200, credits: @Chaoses-Ib).
Date: July 16, 2025.
DateTime claims on creation (#200, credits: @Chaoses-Ib).remove_claim() to Claims (#201, credits: @Chaoses-Ib).Fixup for "Build serde and serde_derive in parallel" (#192, credits: @Enselic).
Build serde and serde_derive in parallel (22% faster builds) (#189, credits: @Enselic).
Add ClaimsValidationRules::disable_valid_at() which optionally skips validation of iat and nbf, that _may_ be present within payload claims #173.
Date: April 12, 2025.
ClaimsValidationRules::disable_valid_at() which optionally skips validation of iat and nbf, that may be present within payload claims #173.Fix bug that prevented compiling with serde-feature enabled.
Date: April 10, 2025.
serde-feature enabled.1.81.0.__Date:__ January 27, 2025. - Bump getrandom to 0.3.0.
Date: January 27, 2025.
getrandom to 0.3.0.Add serde Serialize and Deserialize to TrustedToken, UntrustedToken and Claims (#150, credits: @tomtom5152).
Date: December 10, 2024.
serde Serialize and Deserialize to TrustedToken, UntrustedToken and Claims (#150, credits: @tomtom5152).Updated test vectors for v3.public.
Date: August 28, 2024.
1.80.v3.public.Error::ClaimValidation(ClaimValidationError), where ClaimValidationError now further specifies the validation error (#131, credits: @jpramosi).Add Claims::set_expires_in() (#107, credits: @franklx).
Date: December 12, 2023.
1.70.Claims::set_expires_in() (#107, credits: @franklx).Add Claims::new_expires_in() (#96).
Switch from actions-rs/tarpaulin to cargo-tarpaulin in CI.
Date: March 4, 2023.
Changelog:
p384 to 0.13.01.65.0actions-rs/tarpaulin to cargo-tarpaulin in CI.SymmetricKey, AsymmetricSecretKey and AsymmetricKeyPair now implement Clone.
Date: December 14, 2022.
Changelog:
SymmetricKey, AsymmetricSecretKey and AsymmetricKeyPair now implement Clone.AsymmetricSecretKey now re-computes the public key from the secret seed to check if they match. If they don't an error is returned. Because we use ed2
Date: November 17, 2022.
Changelog:
AsymmetricSecretKey now re-computes the public key from the secret seed to check if they match. If they don't an error is returned. Because we use ed25519-compact crate for Ed25519, if an all-zero seed is used, the creation of AsymmetricSecretKey will panic.Add optional serde support for keys + PASERK ID, to be de/serialized from/to PASERK strings. Also introducing a new optional feature serde (see #26, b
Date: October 15, 2022.
Changelog:
serde support for keys + PASERK ID, to be de/serialized from/to PASERK strings. Also introducing a new optional feature serde (see #26, by @SanchithHegde)ed25519-compact to 2.0.2 (see #72)Fix ed25519-compact imports that broke build after the crate bumped to 1.0.13+
Date: September 23, 2022.
Changelog:
ed25519-compact imports that broke build after the crate bumped to 1.0.13+Add rust-version field to Cargo.toml
Date: September 20, 2022.
Changelog:
1.59.0clippy fixesrust-version field to Cargo.tomlPASERK operations are now implemented for AsymmetricSecretKey and AsymmetricSecretKey instead of AsymmetricKeyPair and AsymmetricKeyPair , respectivel
Date: June 20, 2022.
Changelog:
AsymmetricSecretKey<V2> and AsymmetricSecretKey<V4> instead of AsymmetricKeyPair<V2> and AsymmetricKeyPair<V4>, respectivelysign() operations with public tokens now take only the secret keyV2 and V4 token's AsymmetricSecretKey<> are now defined to contain both the Ed25519 secret seed and the public key (see https://github.com/MystenLabs/ed25519-unsafe-libs)TryFrom<AsymmetricSecretKey<>> for AsymmetricPublicKey<> is now provided for V2 and V4 as wellIntroduce separate crate-features for each version and one for PASERK: v2, v3, v4 and paserk. std, v4 and paserk are enabled by default
Date: June 4, 2022.
Changelog:
1.57.0v3.public tokens (#40)v2, v3, v4 and paserk. std, v4 and paserk are enabled by defaultGenerate trait and implement this for all key-types, removing also SymmetricKey::gen() (#45)ed25519-dalek to ed25519-compact (#48)token::UntrustedToken and token::TrustedToken which are now used by verify()/decrypt() operations.
These allow extracting parts of tokens before and after verification (#47)keys:: have been moved to a new version:: moduleFooter type that makes it easier to create JSON-encoded footers (#52)&str instead of String (#53)Error::Base64Decoding -> Error::Base64Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
__Date:__ November 27, 2021. __Changelog:__ - Update Orion to 0.17 (#39) - Bump MSRV to 1.52
Enable getrandom/js feature and test wasm32-unknown-unknown in CI
Date: November 11, 2021.
Changelog:
getrandom/js feature and test wasm32-unknown-unknown in CI (#37)[Security fix]: Switched from chrono to time crate
Date: October 25, 2021.
Changelog:
chrono to time crate (#30)Error now implements std::error::Error (#27) (by @not-my-profile)Errors enum has be renamed to Error and "error" postfixes have been trimmed from variants (#33)SymmetricKey, AsymmetricPublicKey and AsymmetricSecretKey have been made generic over their versions (#31) (by @not-my-profile)local, public and secret PASERK types for keys (#24)Implement version 4 of the PASETO specification
Date: September 22, 2021.
Changelog:
SymmetricKey, AsymmetricPublicKey and AsymmetricSecretKey now used throughout the API of both version 2 and 4 (#14)Errors::EmptyPayloadError has been addedClaims type to easily define claims for tokens and ClaimsValidationRules to validate such claims.std feature which is enabled by default. This means, that to be no_std, pasetors has to be declared without default features.local/public API which uses the latest version, and automatically handles validation of Claims.Remove Csprng trait from public API and use getrandom instead
Date: June 2, 2021.
Changelog:
Csprng trait from public API and use getrandom instead0.16Switch from base64 to ct-codecs to provide constant-time Base64 encoding/decoding
Date: March 21, 2021.
Changelog:
base64 to ct-codecs to provide constant-time Base64 encoding/decoding__Date:__ October 12, 2020.
Date: October 12, 2020.
Your coding agent can read these notes before it upgrades. Set up the MCP server →