NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #829 most downloaded on Packagist
Symfony MercureBundle
Last release today
07 Oct 2026
Ships fairly regularly
a new release about every 6 months
Nearly every release is documented
notes for 25 of 26 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
26 releases · first in 2018
This removes the symfony/mercure 0.5 deprecations that were triggered on every container boot even when the Hub API was used exclusively
protocol_version to 1.0 now that Mercure hub 1.0 is stable; set protocol_version: 0.x to keep talking to a 0.x hub. Hubs relying on the default now use the __Secure-mercure_access_token cookie name (mercure_access_token when kernel.debug is enabled, as browsers drop __Secure- cookies over plain HTTP; it matches the hub's playground default), and jwt.secret hubs must define the iss, sub and client_id claims in jwt.claims or the container fails to compileprotocol_version also accepts ProtocolVersion enum caseshttp_client per-hub option, to publish through a dedicated HTTP client service (e.g. a scoped client with a short timeout)RemoteHubInterface autowirable, globally for a remote default hub and per hub through named arguments (e.g. RemoteHubInterface $fooHub)symfony/mercure ^0.9Publisher / PublisherInterface / TraceablePublisher services and aliases, and the StaticJwtProvider service (mercure.hub.*.jwt_provider). Apps must use Hub / HubInterface / TraceableHub and StaticTokenProvider (mercure.hub.*.jwt.provider) instead. This removes the symfony/mercure 0.5 deprecations that were triggered on every container boot even when the Hub API was used exclusively (#121)MercureDataCollector::getPublishers() (deprecated since 0.3 in favor of getHubs())Hub and FrankenPhpHub at runtime, through a factory, instead of guessing at container build time: an empty url (an unset or empty MERCURE_URL, which is all Docker Compose can express) now reliably selects FrankenPHP's built-in Mercure hub, which is also autowirable through HubInterface like any other hub. url and public_url both default to null unconditionallypublisher and subscriber per-hub options, an alternative to jwt to sign publisher and subscriber tokens with different keysdefault_hub naming an undefined hub failing with a TypeError instead of a configuration errorTraceableHub keeping the messages of previous requests in long-running processes (e.g. FrankenPHP's worker mode)One column per quarter.
Add support for the Mercure protocol 1.0, alongside the existing 0.x protocol: new protocol_version ( 0.x , default, or 1.0 ) and cookie_name per-hub
protocol_version (0.x, default, or 1.0) and cookie_name per-hub optionsjwt.jwks_uri and jwt.key_id, fetching the signing key from a JSON Web Key Set endpoint via WebTokenFactory instead of jwt.secret (requires web-token/jwt-library, Mercure 1.0 hubs only)jwt.claims (e.g. iss/sub/client_id), required by RFC 9068 when using jwt.secret/jwt.jwks_uri on a protocol_version: 1.0 hub; aud defaults to the hub's own URL when not set. Missing required claims fail at container compile time, and a 0.x hub without jwt.claims keeps minting byte-identical legacy tokens (no DefaultClaimsTokenFactory wrapping, no automatic aud)symfony/mercure ^0.8symfony/mercureprotocol_version (0.x, default, or 1.0) and cookie_name per-hub optionsjwt.secret convenience option now uses LcobucciFactory's Mercure protocol 1.0 support on a protocol_version: 1.0 hubjwt.jwks_uri and jwt.key_id, fetching the signing key from a JSON Web Key Set endpoint via WebTokenFactory instead of jwt.secret (requires web-token/jwt-library, Mercure 1.0 hubs only)jwt.algorithm no longer has a single default, as the two token factories name algorithms differently: it defaults to hmac.sha256 with jwt.secret (LcobucciFactory) and to the JWA name HS256 with jwt.jwks_uri (WebTokenFactory, which also accepts PS256/PS384/PS512 and EdDSA)jwt.claims (e.g. iss/sub/client_id), required by RFC 9068 when using jwt.secret/jwt.jwks_uri on a protocol_version: 1.0 hub; aud defaults to the hub's own URL when not set. Missing required claims fail at container compile time, and a 0.x hub without jwt.claims keeps minting byte-identical legacy tokens (no DefaultClaimsTokenFactory wrapping, no automatic aud)symfony/mercure ^0.8symfony/mercure's Hub/FrankenPhpHub constructor parameter reorder ($cookieName before $protocolVersion) and its Grant-based TokenFactoryInterface::create(); jwt.subscribe/jwt.publish are now wired in as one publish and one subscribe Grant, always both present so the legacy claim's shape is unchanged for hubs configuring neithersymfony/mercureExtend the Extension class from the DependencyInjection component
Extension class from the DependencyInjection componentsymfony/mercure dependency to supported versionsbranch-aliasFix Twig extension registration when using Symfony Mercure 0.7 (again)
Fix Twig extension registration when using Symfony Mercure 0.7
Add support for FrankenPHP's mercure_publish() function
mercure_publish() functionTurboStreamListenRendererExplicitly mark method parameters as nullable
Allow Symfony 7
Support for symfony/ux-turbo 2.9 using symfony/stimulus-bundle
symfony/ux-turbo 2.9 using symfony/stimulus-bundleCompatibility with lcobucci/jwt 5.0
lcobucci/jwt 5.0fix: use the right argument index for Authorization cookie lifetime by @chalasr in #69
Full Changelog: v0.3.4...v0.3.5
Add support for JWT signers requiring a passphrase
jwt nor the jwt_provider configuration key is defined.Deprecate enable_profiler configuration
enable_profiler configurationFull compatibility with PHP 7.1
Add a configuration option to set a default expiration for the JWT and the cookie when using the Authorization class
Authorization classAdd integration with symfony/ux-turbo
symfony/mercure 0.5symfony/ux-turbomercure.publisher tag on publisher servicesExpose privateness of published messages in profiler panel
Fix a bug in the debugger panel
Compatibility with Mercure 0.10
Fix a bug preventing the profiler to work
Fix compatibility with Symfony 5
Fix a crash in MercureDataCollector
MercureDataCollectorAutowire Symfony\Component\Mercure\PublisherInterface instances (using Symfony\Component\Mercure\Publisher for autowiring is deprecated)
Symfony\Component\Mercure\PublisherInterface instances (using Symfony\Component\Mercure\Publisher for autowiring is deprecated)Inject the http_client service when available
http_client service when availableFix a deprecation triggered by the TreeBuilder
TreeBuilderNothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →