NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #582 most downloaded on Packagist
This bundle provides JWT authentication for your Symfony REST API
Last release 9 months ago
20 Dec 2025
Release timing varies
gaps range from 8 days to 12 months
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
93 releases · first in 2014
Fixed typo in UPGRADE-3.0.md by @TimoBakx in #1271
Full Changelog: v3.1.1...v3.2.0
One column per quarter.
Update 10-web-token.rst by @cosminsandu in #1235
Full Changelog: v3.1.0...v3.1.1
feature: fix deprecation of Extension by @Chris53897 in #1226
Full Changelog: v3.0.0...v3.1.0
CI: Fix deprecations from ApiPlatform 3.2 & PHPUnit 10 by @chalasr in #1221
Full Changelog: v2.21.0...v3.0.0
⚠️ This is the LAST 2.X FEATURE RELEASE ⚠️ The branch 2.x is now bugfix-only.
⚠️ This is the LAST 2.X FEATURE RELEASE ⚠️ The branch 2.x is now bugfix-only.
Full Changelog: v2.20.3...v2.21.0
Fix for PHP <7.4 compatibility by @fracsi in #1183
Full Changelog: v2.20.2...v2.20.3
Fix for PHP <7.4 compatibility by @fracsi in #1174
Full Changelog: v2.20.1...v2.20.2
Removed constructor property promotion to fix compatibility with PHP 7.x by @webhdx in #1172
Support Symfony 7 by @endroid in #1165
Full Changelog: v2.19.1...v2.20.0
Fix missing array claims BC break in 2.9.0 by @ostrolucky in #1144
Full Changelog: v2.19.0...v2.19.1
bug \#1120 Remove deprecation symfony 6.3 (@maxhelias)
bug \#1115 Fix compatibility with lcobucci v3.4 (maxhelias)
bug \#1109 Replaced deprecated ValidAt() with LooseValidAt() (carcabot)
bug \#1069 Improve user_identity_field deprecation message (lobodol)
remove_token_from_body_when_cookies_used (usu)feature \#1037 Deprecate user_identity_field config option (chalasr)
allow_no_expiration option to allow validating tokens without ttl (pluk77)## 2.15.1 (2022-04-06)
Nothing published for this version
feature \#995 Add Request object into AuthenticationFailureEvent (dmytro-shulyakov)
bug \#972 Typo-Fix in the ChainUserProvider (KhorneHoly)
bug \#969 Fix PHP 8.1 deprecation - avoid passing null to is_file() (chalasr)
remove_token_from_body_when_cookies_used config option (TjorvenB)bug \#961 Allow symfony/deprecations-contract v3.0 (bravik)
bug \#942 Fix Symfony 5.3 compatibility (chalasr)
feature \#923 Add 3 new getter method to JWTTokenAuthenticator (fd6130)
feature \#916 Allow to use custom authenticator by extending JWTAuthenticator (fd6130)
JWTAuthenticator::start method return type to more generic Response type (aurimasniekis)AuthenticatorInterface::createToken() (Symfony 5.4) (chalasr)bug 66ec1e0 Fix missing import (chalasr)
bug \#897 Fix unexpected deprecation about Guard (bis) (chalasr)
bug \#895 Fix unexpected deprecation about Guard (chalasr)
bug \#887 JWTAuthenticator logic fix (ergnuor)
bug \#886 Fix remaining deprecations on Symfony 5.3 (chalasr)
bug \#884 Remove development files from releases (chalasr)
bug \#878 Handle misc. Symfony 5.3 deprecations, update CI config (mbabker)
bug a175d6dab9 Prevent user enumeration via response content (chalasr)
bug \#840 [Security] On Authentication failure, replace MessageData (mpiot)
bug \#835 Fix #834: Re-add namshi/jose as required dependency until v3 (filisko)
bug \#833 KeyLoaderInterface::getPassphrase() might return null and we need a string (drupol)
bug a175d6dab9 Prevent user enumeration via response content (chalasr)
bug \#827 Use named constructor for lcobucci/jwt Ecdsa signers (chalasr)
bug \#815 Fix compatibility for lcobucci/jwt v3.x (bis) (chalasr)
bug \#813 Fix undefined variable (chalasr)
bug \#804 Fix ability to set extra standard claims in the input payload (bis) (chalasr)
bug \#801 Fix ability to set extra standard claims in the input payload (chalasr)
bug \#797 Fix support for lcobucci/jwt v3.4 and 4.0 (chalasr)
feature \#790 Fix Symfony 5.2 getProviderKey deprecation (ogizanagi)
bug #780 Add deprecation message argument to JWTFactory.php (chrBrd)
bug \#755 Drop php 5.5 compat, Test against php 7.4 + symfony 5.1 and fix deprecations (acrobat)
feature \#753 Add set_cookies option to store JWT in secure cookies (chalasr)
set_cookies option to store JWT in secure cookies (chalasr)bug \#669 Fix dispatch signature on SF > 4.3 (Webonaute)
bug \#644 Fix FC/BC layer for EventDispatcher (nicolas-grekas)
bug \#637 Fix deprecations on symfony/event-dispatcher:4.3 (chalasr)
bug \#577 Fix argument order in JWTProvider service declaration (fjogeleit)
bug \#554 Fix deprecations on Symfony 4.2 (chalasr)
bug \#542 Fix missing implemenets breaking JWT header alteration (tucksaun)
bug \#525 Make openssl key loader service deprecated (Faecie)
bug \#522 Fix clock skew + deprecation message (chalasr)
bug \#515 Re-add namshi/jose as an hard requirement until 3.0 (chalasr)
feature \#508 Replace namshi/jose by lcobucci/jwt (chalasr)
lexik:jwt:generate-token command (sroze)Nothing published for this version
bug \#399 Fix sf3.4 command autoregistration deprecation (ogizanagi)
bug \#398 Fix Symfony 4 compatibility (benji07)
bug \#356 Dont use DefinitionDecorator on Symfony 3.3+ (chalasr)
Your coding agent can read these notes before it upgrades. Set up the MCP server →