NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3082 most downloaded on npm
GitHub App authentication for JavaScript
Last release 16 days ago
01 Sep 2026
Release timing varies
gaps range from 4 weeks to 6 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
115 releases · first in 2019
types: add installationId to InstallationAccessTokenAuthentication
One column per quarter.
## 3.5.3 (2021-06-28) ### Bug Fixes * add webhook deliveries APIs
typescript: corret types for auth({ type: "installation", installationId, factory })
Do not intercept auth.hook(request, "POST https://github.com/login/oauth/access_token") requests
# 3.5.0 (2021-06-12) ### Features * set error.response
typescript: installation authentication type
throw helpful error when appId or privateKey is set to a falsy value
# 3.3.0 (2021-03-24) ### Features * typescript: export types
factory option for auth({ type: "oauth-user" })
auth({ type: "oauth-user" }). Deprecates auth({ type: "oauth" })
createAppAuth({ id, privateKey }) is no longer supported. Use createAppAuth({ appId, privateKey }) instead
auth: throw Error when auth type is not a valid one
## 2.10.6 (2021-01-25) ### Bug Fixes * deps: lock file maintenance
add missing paths to list of paths that require app auth (#236) (2067a8a) thanks @suhaibmujahid
deps: bump @octokit/types from 5.5.0 to 6.0.0
README: three authentication strategies
pass all strategy options to auth factory
strategyOptions.id is now strategyOptions.appId
# 2.8.0 (2020-10-26) ### Features * factory auth option
# 2.7.0 (2020-10-15) ### Features * log option parameter
typescript: resolve TypeScript incompatibility
app authentication: Handle time difference between system and GitHub API time in JWT claims
improve error message in case of 401 after the retries in the first 5 seconds
reduce the retry time to account for replication lag from 1 minute to 5 seconds
do not remail trailing | from cache values
throw helpful message in case permissions cannot be read out from cache
auth.hook() uses app auth for marketplace URL
throw helpful error on auth({ type: "installation" }) if installationId option is not set
deps: bump universal-user-agent from 5.0.0 to 6.0.0
## 2.4.9 (2020-07-17) ### Bug Fixes * auth.hook() and custom cache
deps: bump lru-cache from 5.1.1 to 6.0.0
deps: bump @octokit/types from 4.1.9 to 5.0.0
retry requests on 401 response within first minute
workaround incomplete POST /app/installations/:installation_id/access_tokens response types
package: update @octokit/request-error to version 2.0.0
package: update universal-user-agent to version 5.0.0
auth.hook() uses app auth for "https://api.github.com/app/installations"
handle error response with 200 status code from OAuth endpoint
package: update @octokit/types to version 2.0.0
# 2.3.0 (2019-10-25) ### Features * implementAuthInterface
improve TypeScript definitions via @octokit/types
package: version in published package
README: module name in usage examples
package: update universal-user-agent to version 4.0.0
# 2.1.0 (2019-09-02) ### Features * add browser support
JWT: set iat to -30s as described in README
auth(options) now requires options.type to be set to "app" or "installation". The returned authentication object no longer has headers and query keys.
auth(options) now requires options.type to be set to "app" or "installation". The returned authentication object no longer has headers and query keys. Use auth.hook() to send requests with automatically applied authentication based on the request URL instead.package: update universal-user-agent to version 3.0.0
package: update @octokit/request to version 5.0.0
# 1.2.0 (2019-07-02) ### Features * installationId strategy option
auth({permissions}). permissions and singleFileName (if applicabale) are now always included in authentication object
# 1.0.0 (2019-06-12) ### Features * initial version (d6ba0f9) * options.cache
Your coding agent can read these notes before it upgrades. Set up the MCP server →