NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #582 most downloaded on Packagist
This bundle provides JWT authentication for your Symfony REST API
Last release 9 months ago
20 Dec 2025
Release timing varies
gaps range from 8 days to 12 months
Nearly every release is documented
notes for 58 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
93 releases · first in 2014
feature \#330 Allow empty ttl for testing purpose (chalasr)
bug \#325 Move ttl is_numeric check from build time to runtime to allow use of %env()% (DrBenton)
One column per quarter.
feature \#312 Ease sharing keys between parties (chalasr)
bug \#302 Return user object from User Provider refresh (MisterGlass)
feature \#278 Add JWTUserProvider for loading users from the JWT itself (chalasr)
bug \#285 Avoid validating key paths before container compilation (chalasr)
getProviderKey() to JWTUserToken (eXtreme)feature \#262 Add composer test script (chalasr)
feature \#257 Set autowiring types on services with many alternatives
feature \#184 [Security] Deprecate current system in favor of a JWTTokenAuthenticator (Guard) (chalasr)
feature #249 Avoid setting exp claim from JWTManager (chalasr)
feature #246 Add a simple built-in encoder based on lcobucci/jwt (chalasr)
feature #184 [Security] Deprecate current system in favor of a JWTTokenAuthenticator (Guard) (chalasr)
feature #218 Add more flexibility in token extractors configuration (chalasr)
feature #217 Refactor TokenExtractors loading for easy overriding (chalasr)
feature #196 Make *_key_path config options not mandatory (chalasr)
feature #162 [Encoder] Handle OpenSSL/phpseclib engines and algorithms (chalasr)
#175 Stop ensuring support for PHP versions smaller than 5.0 (chalasr)
#167 and #169 Stop ensuring support Symfony versions smaller than 2.8 (chalasr)
Nothing published for this version
feature \#200 Deprecate injection of Request instances (chalasr)
feature \#188 Add JWTNotFoundEvent (chalasr)
bug \#159 Fix anonymous access by removing the AuthenticationCredentialsNotFoundException (chalasr)
feature \#157 Allow to set a custom response in case of authentication failure or invalid/not found token (chalasr)
feature \#133 Always call for master request from request stack (stloyd)
Nothing published for this version
feature \#126 Use requestStack instead of request (SmurfyFR)
feature \#117 Allow empty ttl (soyuka)
bug \#101 Fatal error on console cache:clear (ngandemer)
feature \#100 Add authentication_listener option (yelmontaser)
bug \#92 Fix authentication event propagation (mRoca)
feature \#73 add JWTEncodedEvent so JWT string is available after its creation (9orky)
feature \#71 Fixing a missing use statement for Reference (adetwiler)
bug \#70 fixed deprecated errors for symfony 2.6 plus (slashfan)
feature \#63 Improve JWTProvider (JJK801)
Nothing published for this version
feature \#45 Adding AuthenticationException to the AuthenticationFailureEvent (ghost)
feature \#28 Improve response and dispatch event in AuthenticationFailureHandler (EmmanuelVella)
feature \#27 Added encoder / decoder service customization \(\#24\) (slashfan)
Nothing published for this version
feature \#15 Added JWT Creator service (gfreeau)
Nothing published for this version
feature \#10 Added ability to throw exceptions for handling later and to disable the catch-all entry point (gfreeau)
Your coding agent can read these notes before it upgrades. Set up the MCP server →