NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4311 most downloaded on npm
GitHub Apps toolset for Node.js
Last release 2 months ago
02 Aug 2026
Release timing varies
gaps range from 8 days to 9 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
19 versions withdrawn
withdrawn after publishing
8 years old
104 releases · first in 2018
typescript: avoid import { App } from "../...d.ts" in types export
remove type imports from "http" for Deno compatibility
One column per quarter.
v12 (#232) (7c48a3a), closes #232
sign and webhooks.sign no default to sha256 algorithm. In order to continue to use sha1, replacesign(secret, payload)
with
sign({ secret, algorith: "sha1" }, payload)
webhooks.sign() and webhooks.verify() are now asynchronoussign and verify methods are no longer exported. Use @octokit/webhooks-methods package insteaddeps: bump @octokit/webhooks to 9.0.0
app.webhooks.sign now defaults to sha256 algorithm. In order to continue to use sha1, replace
app.webhooks.sign now defaults to sha256 algorithm. In order to continue to use sha1, replace
app.webhooks.sign(secret, payload)
with
app.webhooks.sign({ secret, algorith: "sha1" }, payload)
app.webhooks.sign() and app.webhooks.verify() are now asynchronous
deps: remove unused package deprecation
typescript: fix types for octokit instances in app.oauth.* APIs'
typescript: Inherit types from defaults.Octokit set via App.defaults({ Octokit })
## 11.3.1 (2021-04-05) ### Bug Fixes * typescript: app.oauth type
typescript: derive octokit type from Octokit option
createNodeMiddleware: log option
# 11.1.0 (2021-03-26) ### Features * App.defaults(options)
getNodeMiddleware() export has been removed. Use createNodeMiddleware() instead
getNodeMiddleware() export has been removed. Use createNodeMiddleware() insteadconst { token, scopes } = app.oauth.createToken(options) is now const { authentication: { token, scopes } } = app.oauth.createToken(options)const url = app.oauth.getAuthorizationUrl() is now const { url } = app.oauth.getWebFlowAuthorizationUrl();before_delete action removed for token and authorization OAuth events. We could add them back, but it would require an additional request, we'd like to see if there are people why actually use these events.app.oauth.getUserOctokit()app.oauth.refreshToken()app.oauth.scopeToken()app.oauth.createToken() now supports the device flowcreateNodeMiddleware(). Deprecates getNodeMiddleware()
## 10.2.2 (2021-02-19) ### Bug Fixes * README: usage example
deps: update dependency @octokit/auth-app to v3
typescript: options.oauth.allowSignup is optional and boolean
types: add explicit return type to webhooks() function
update dependency @octokit/webhooks to v8. Pass unauthenticated octokit instance to webhook event handler in case the event payload has no "installati
add implementation of eachRepository({ installationId }, callback) (#189) thanks @tmadeira, @oscard0m, @wolfy1339
## 10.0.3 (2021-01-25) ### Bug Fixes * deps: lock file maintenance
## 10.0.2 (2020-12-03) ### Bug Fixes * update to @octokit/types v6
README: replace :param notation with {param}
initial version of the all new @octokit/app
initial version of the all new @octokit/app
deprecate in favor of @octokit/auth-app
deps: bump lru-cache from 5.1.1 to 6.0.0
# 4.2.0 (2020-02-13) ### Features * App.VERSION
change comment to more accurately reflect intent
Add all API options to getInstallationAccessToken
travis: drop Node 6 tests, add Node 12 tests
package: update @octokit/request to version 5.0.0
## 3.0.1 (2019-06-12) ### Bug Fixes * add 30s leeway to JWT expiry
`js const App = require('@octokit/app') `
## 2.2.5 (2019-05-20) ### Bug Fixes * JWT expiration 1min -> 10min
typescript: id parameter in constructor should be a number
package: update @octokit/request to version 3.0.0
Typescript: LRUCache definition
typescript: installation_id → installationId
typescript: Add typings for the module
# 2.1.0 (2018-12-16) ### Features * add baseUrl App option
app.getInstallationAccesToken() had a typo and was renamed to app.getInstallationAccessToken()
app.getInstallationAccesToken() had a typo and was renamed to app.getInstallationAccessToken()Thanks @chrisrowe 💐
# 1.1.0 (2018-11-24) ### Features * caching installation tokens
# 1.0.0 (2018-11-24) ### Features * initial version
Your coding agent can read these notes before it upgrades. Set up the MCP server →