NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #2647 most downloaded on Packagist
External authentication via OAuth and OpenID for the Yii framework
Last release 8 days ago
29 Sep 2026
Ships fairly regularly
a new release about every 6 months
Nearly every release is documented
notes for 35 of 35 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
37 releases · first in 2014
…clients to avoid PHP 8.4 implicit nullable types deprecation (@terabytesoftw)
BaseOAuth::$accessToken (mspirkov)BaseOAuth::refreshAccessToken() when no refresh token exists (kalmer)InvalidResponseException constructor (@cyansoftdev)OAuthToken parameters in OAuth1 and Facebook clients to avoid PHP 8.4 implicit nullable types deprecation (@terabytesoftw)hash_hmac() and rawurlencode() in Facebook and OAuth1 clients to avoid PHP 8.5 deprecations (@terabytesoftw)@property annotations in case of different types in getters and setters (mspirkov)vk.ru domains instead of vk.com (DMITRII1548)@property tags (mspirkov)One column per quarter.
Bug #392: Now using array as default value for token_endpoint_auth_methods_supported in OpenIdConnect::applyClientCredentialsToRequest() (strtob, rher
token_endpoint_auth_methods_supported in OpenIdConnect::applyClientCredentialsToRequest() (strtob, rhertogh)Enh #387: Use appropriate exception if client does not exist (eluhr)
Enh GHSA-w8vh-p74j-x9xp: Improved security for OAuth1, OAuth2 and OpenID Connect clients by using timing attack safe string comparsion (rhertogh)
authCodeVerifier if PKCE is enabled and clearing it after usage (rhertogh)ClientErrorResponseException when the response code in BaseOAuth::sendRequest() is a 4xx (rhertogh)Bug #351: Unable to set TokenParamKey in OAuth2 config, gets hard overwritten in OAuth2::createToken() (DSTester)
Bug #354: Fix PHP 8.1 deprecated message in BaseOAuth stripos(): Passing null to parameter #1 ($haystack) of type string is deprecated (marty-macfly)
stripos(): Passing null to parameter #1 ($haystack) of type string is deprecated (marty-macfly)Bug #330: OpenID Connect client now defaults to 'client_secret_basic' in case token_endpoint_auth_methods_supported isn't specified (rhertogh)
'client_secret_basic' in case token_endpoint_auth_methods_supported isn't specified (rhertogh)aud claim can either be a string or a list of strings (azmeuk)aud nonce is passed from the authentication request to the token request (azmeuk)nonce when refreshing the access token (rhertogh)AuthAction::$defaultClientId and AuthAction::getClientId() (ditibal)'id_token' claim for getUserAttributes() if userinfo_endpoint is not available (rhertogh)userinfo_endpoint response (rhertogh)Enh #318: Add statusCode from response to init InvalidResponseException in sendRequest method of yii\authclient\BaseOAuth class (vleedev)
statusCode from response to init InvalidResponseException in sendRequest method of yii\authclient\BaseOAuth class (vleedev)random_int() when generating OAuth1 nonce (samdark)Chg #315: Add proof key for code exchange PKCE support to oauth2 (AdeAttwood)
Bug #312: do not refresh access token if it is not expired (albertborsos)
Bug #309: Try to refresh token in BaseOAuth->beforeApiRequestSend() if BaseOAuth->autoRefreshAccessToken = true instead of throwing "Invalid access to
BaseOAuth->beforeApiRequestSend() if BaseOAuth->autoRefreshAccessToken = true instead of throwing "Invalid access token" exception (marty-macfly)Bug #292: Updated GitHub token transfer method according to https://developer.github.com/changes/2019-11-05-deprecated-passwords-and-authorizations-ap…
Bug #288: Default request option for turning off SSL peer verification was removed (Rutger, samdark)
Enh #217: Replace spomky-labs/jose by JWT Framework (marty-macfly, smcyr)
Enh #276: Bumped VK API version to 5.95, according to developers recommendation (EvgeniyRRU)
Chg #273: OpenIdConnect::validateClaims() is now protected (samdark)
OpenIdConnect::validateClaims() is now protected (samdark)Bug #270: Updated Facebook icon to match brand guidelines (ServerDotBiz)
Bug #252: Fix bug when OAuthToken is incorrectly instantiated if configuration array has incorrect order (rob006)
OAuthToken is incorrectly instantiated if configuration array has incorrect order (rob006)Bug #266: Updated Google client image (nurielmeni)
Enh #258: Use Google Sign-in API instead of Google Plus in yii\authclient\clients\Google as Google Plus is deprecated (alexeevdv)
AuthAction (samdark, lab362)yii\authclient\clients\Google as Google Plus is deprecated (alexeevdv)AuthAction (albertborsos)Bug #241: Unset parameter scope on defaultReturnUrl for OAuth2 class since it was causing bad request response from Google provider (okiwan)
scope on defaultReturnUrl for OAuth2 class since it was causing bad request response from Google provider (okiwan)Bug #211: RsaSha was not passing $key to openssl_pkey_get_private() in generateSignature() (cfhodges)
RsaSha was not passing $key to openssl_pkey_get_private() in generateSignature() (cfhodges)OpenIdConnect client send token as bearer auth instead of querystring parameter (lukos)Enh #187: URL endpoints for authUrl and tokenUrl for yii\authclient\clients\LinkedIn updated (Felli)
authUrl and tokenUrl for yii\authclient\clients\LinkedIn updated (Felli)yii\authclient\AuthAction refactored to use yii\web\Application::$request for request data access (klimov-paul)yii\authclient\AuthAction::$cancelCallback allowing custom handling for authentication cancelation (terales, klimov-paul)Bug: Usage of deprecated yii\base\Object changed to yii\base\BaseObject allowing compatibility with PHP 7.2 (klimov-paul)
\yii\authclient\widgets\GooglePlusButton consider 'immediate_failed' as instant auth error (klimov-paul)yii\base\Object changed to yii\base\BaseObject allowing compatibility with PHP 7.2 (klimov-paul)yii\authclient\clients\TwitterOAuth2 supporting 'application-only authentication' workflow for Twitter (klimov-paul)apiVersion at yii\authclient\clients\VKontakte (isudakoff)yii\authclient\clients\VKontakte::initUserAttributes() now throws verbose exception on unexpected API response instead of PHP error (klimov-paul)Bug #152: Fixed \yii\authclient\OAuth1::fetchRequestToken() skips formatting for yii\httpclient\Request (klimov-paul)
\yii\authclient\OAuth1::fetchRequestToken() skips formatting for yii\httpclient\Request (klimov-paul)\yii\authclient\OAuth1::composeSignatureBaseString() does not take URL query string into account (klimov-paul)\yii\authclient\OpenIdConnect supporting OpenID Connect protocol (klimov-paul)\yii\authclient\signature\RsaSha and \yii\authclient\signature\HmacSha supporting general 'SHAwithRSA' and 'HMAC SHA' signature methods (klimov-paul)\yii\authclient\OAuth2::authenticateUserJwt() supporting authentication via JSON Web Token (JWT) (klimov-paul)yii\authclient\clients\Facebook (klimov-paul)yii\authclient\clients\Facebook (klimov-paul)yii\authclient\clients\Facebook::$autoRefreshAccessToken is now disabled by default (klimov-paul)Bug #135: Fixed \yii\authclient\OAuth1::fetchRequestToken() duplicates auth params in the request body, which may cause error on some OAuth 1.0 provid
\yii\authclient\OAuth1::fetchRequestToken() duplicates auth params in the request body, which may cause error on some OAuth 1.0 providers (klimov-paul)$ to jQuery to prevent global conflicts in widget JavaScript (Ariestattoo)appsecret_proof generation for the API requests at yii\authclient\clients\Facebook (blackhpro, SDKiller, klimov-paul)Bug #128: Fixed \yii\authclient\BaseClient::createRequest() does not apply defaultRequestOptions and requestOptions (klimov-paul)
\yii\authclient\BaseClient::createRequest() does not apply defaultRequestOptions and requestOptions (klimov-paul)\yii\authclient\OAuth1::fetchRequestToken() unable to unset current access token (klimov-paul)\yii\authclient\OAuth1::authorizationHeaderMethods option allowing to control request methods, which require authorization header (klimov-paul)authUrl and tokenUrl for yii\authclient\clients\VKontakte updated (KhristenkoYura)Enh #27: This extension no longer require PHP 'cURL' extension to be installed (klimov-paul)
\yii\authclient\OAuth2::authenticateClient() (klimov-paul)\yii\authclient\BaseOAuth::api() (klimov-paul)\yii\authclient\OAuth1::fetchAccessToken() (klimov-paul)\yii\authclient\widgets\AuthChoice simplified (klimov-paul)yii2-httpclient library for the HTTP requests (klimov-paul)\yii\authclient\OAuth2::authenticateUser() (klimov-paul)clientLink() and renderMainContent() of yii\authclient\widgets\AuthChoice reworked to return HTML instead of echo (klimov-paul)OAuth2 for preventing cross-site request forgery (klimov-paul)Bug #37: Fixed \yii\authclient\widgets\AuthChoice overrides any tag click behavior between begin() and end() methods (klimov-paul)
\yii\authclient\widgets\AuthChoice overrides any <a> tag click behavior between begin() and end() methods (klimov-paul)yii\authclient\clients\GitHub now retrieves user email even if it is set as 'private' at GitHub account (klimov-paul)Bug #25: yii\authclient\BaseOAuth now can be used without without session application component available (klimov-paul)
yii\authclient\BaseOAuth now can be used without without session application component available (klimov-paul)attributeNames field to yii\authclient\clients\Facebook, which allows definition of attributes list fetched from API (samdark)yii\authclient\clients\Facebook has been increased up to 860x480 (lame07, klimov-paul)Chg: #7754: yii\authclient\clients\GoogleOpenId is now deprecated because this auth method is no longer supported by Google as of April 20, 2015 (klim…
yii\authclient\OAuth1 (klimov-paul)yii\authclient\BaseOAuth::processResponse() removed (klimov-paul)attributeNames field to yii\authclient\clients\VKontakte and yii\authclient\clients\LinkedIn, which allows definition of attributes list fetched from API (klimov-paul)yii\authclient\widgets\AuthChoice fixed to follow the Google Brand guidelines (klimov-paul)yii\authclient\clients\VKontakte now gets attributes from access token also (klimov-paul)yii\authclient\clients\GooglePlus added to support Google recommended auth flow (klimov-paul)yii\authclient\clients\GoogleOpenId is now deprecated because this auth method is no longer supported by Google as of April 20, 2015 (klimov-paul)Enh #6892: Default value of yii\authclient\clients\Twitter::$authUrl changed to 'authenticate', allowing usage of previous logged user without request
yii\authclient\clients\Twitter::$authUrl changed to 'authenticate', allowing usage of previous logged user without request an access (kotchuprik)Bug #6502: Fixed \yii\authclient\OAuth2::refreshAccessToken() does not save fetched token (sebathi)
\yii\authclient\OAuth2::refreshAccessToken() does not save fetched token (sebathi)\yii\authclient\AuthAction::cancelUrl (klimov-paul)Bug #6000: Fixed CCS for yii\authclient\widgets\AuthChoice does not loaded if popupMode disabled (klimov-paul)
yii\authclient\widgets\AuthChoice does not loaded if popupMode disabled (klimov-paul)Enh #5135: Added ability to operate nested and complex attributes via yii\authclient\BaseClient::normalizeUserAttributeMap (zinzinday, klimov-paul)
yii\authclient\BaseClient::normalizeUserAttributeMap (zinzinday, klimov-paul)Bug #3633: OpenId return URL comparison advanced to prevent url encode problem (klimov-paul)
yii\authclient\widgets\AuthChoice does not preserve initial settings while opening popup (klimov-paul)yii\authclient\BaseOAuth::api() method (klimov-paul)yii\authclient\InvalidResponseException added for tracking invalid remote server response (klimov-paul)- Initial release.
Your coding agent can read these notes before it upgrades. Set up the MCP server →