NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3456 most downloaded on Packagist
A simple JSON Web Token library for PHP.
Last release 1 months ago
29 Aug 2026
Ships fairly regularly
a new release about every 3 months
Nearly every release is documented
notes for 41 of 42 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
44 releases · first in 2015
Fixed: Added validation for length of decompressed data where zip:DEF
zip:DEFAdded: Check for presence of alg header in JWT
One column per quarter.
Fixed: Added validation to p2c parameter in PBES2
p2c parameter in PBES2Added: Error codes in BinaryEncodingException, CryptException and KeyException to provide more useful error diagnosis
kid) to use full RFC7517 thumbnailFixed: PHP 8.4 deprecates implicitly nullable parameters in function signatures
Fixed: Incorrect RSAKey::getSize() if leading zero byte is not present in two's complement encoding
RSAKey::getSize() if leading zero byte is notFixed: Uncaught SodiumException if an error occurs in functions that use libsodium
SodiumException if an error occurs in functionsRemoved: Support for PHP 7.3 and 7.4
jwkstool command-line tool and associated dependenciessymfony/console). jwkstool is now availablekelvinmo/jwkstoolFixed: Issue with gmp_pow for certain versions of PHP
Fixed: RSAKey cannot parse PKCS#8 encoded RSA private keys
RSAKey cannot parse PKCS#8 encoded RSA private keys (#206)Fixed: Deprecation warning in constructor of AESGCMKeyWrap
Changed: Providing invalid JSON tokens into JWT::deserialise() and JWE::decrypt() will throw an InvalidTokenException instead of InvalidArgumentExcept
InvalidTokenException instead of
InvalidArgumentExceptionJWT and JWE methods now check for validity of
algorithm classesChanged: Update dependency on symfony/console to support v7.0
symfony/console to support v7.0Fixed: Throw a KeyException when loading an invalid PEM-encoded RSAKey
KeyException when loading an invalid PEM-encoded
RSAKeyAdded: Support for Ed25519 signatures and X25519 key derviation algorithms
Ed25519 signatures and X25519 key derviation
algorithmsA128GCMKW,
A192GCMKW and A256GCMKW)box to package the jwkstool utilityAlgorithm (now renamed to BaseAlgorithm)
and Key to extract interfaces (into AlgorithmInterface and
KeyInterface respectively)kid parameter no longer automatically generated
when a Key object is created. Use Key::getKeyId(true) or
KeySet::add(..., true) to generate a key IDFixed: Incorrect key selection when encrypting/decrypting keys in ECDH-ES+AxxxKW
jwkstoolChanged: Split SimpleJWT\Crypt namespace into multiple namespaces, one for each algorithm type
SimpleJWT\Crypt namespace into multiple namespaces, one
for each algorithm type (#60)JWT and JWE now derives from a common parent class Token\UnexpectedValueException instead of returning false if the input
cannot be decodedDeprecated: Helper::getObject() and Helper::getJWTObject() have been replaced by Helper::decode() and Helper::decodeFully() respectively, and will be…
Changed: Updated symfony/console package version
symfony/console package versionDeprecated: Helper::getJWTObject() now ignores the $jwe_kid parameter and will be removed in future versions
$format parameter (which
is already ignored)alg header) is not valid$jwe_kid parameter
and will be removed in future versionsAdded: Support for Elliptic Curve Diffie-Hellman Ephemeral Static algorithms
Nothing published for this version
Nothing published for this version
Fixed: typos in documentation leading to deprecation error
Fixed: Undefined index when calling JWT::deserialise() and JWE::decrypt() with an unrecognised token format
- Added: Support for PHP 8
Added: Support for AES GCM family of algorithms
Fixed: Uninitialised values in SimpleJWT\JWT::deserialise() for JWTs encoded in JSON serialisation format
Fixed: Composer dependencies on symfony/console for PHP 7 compatibility
symfony/console for PHP 7 compatibility
(#22)Deprecated: SimpleJWT\Keys\Key::getSignature() - use SimpleJWT\Keys\Key::getThumbnail() instead
Fixed undefined variable error when using JWE with a symmetric key
Refactored key signature methodology to align with RFC 7638
Fixed incorrect handling of kid when using symmetric encryption
Fixed incorrect encoding of RSA keys into PEM
Nothing published for this version
Fixed incorrect decoding of PEM-encoded EC private keys
Refactored code to add deserialise function
Support newer versions of OpenSSL used in PHP 7, which uses lowercase cipher and message digest names
Fixed namespace error in documentation blocks
Fixed syntax error when throwing exception as a result of an invalid COMPACT_FORMAT token
Fixed bug in jwkstool in referencing renamed method in KeySet
Fixed bug caused by dependency issues with symfony/composer. The of this library is now locked to 2.7.*
symfony/composer. The of this library is now locked to 2.7.*Enhanced compatibility with PHP 7
[1.1.3]: https://github.com/kelvinmo/simplejwt/compare/v1.1.2...v1.1.3 [1.1.2]: https://github.com/kelvinmo/simplejwt/compare/v1.1.1...v1.1.2 [1.1.1]:
Your coding agent can read these notes before it upgrades. Set up the MCP server →