NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3516 most downloaded on npm
GitHub OAuth App authentication for JavaScript
Last release 1 months ago
01 Sep 2026
Release timing varies
gaps range from 2 weeks to 9 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
66 releases · first in 2019
deps: update dependency @octokit/types to v18
deps: update dependency @octokit/types to v17
One column per quarter.
deps: update dependency @octokit/types to v16
deps: update dependency @octokit/types to v15
deps: update octokit monorepo (major)
stop testing against NodeJS v18
deps: update dependency @octokit/types to v14
deps: bump Octokit deps to mitigate ReDos vulnerability
deps: bump Octokit deps to fix Deno compat
pkg: only build one bundle and add default fallback export
# 8.1.0 (2024-04-03) ### Features * security: Add provenance
deps: update dependency @octokit/types to v13
pkg: add main entry point (#425) (47c32cb), closes octokit/core.js#662
## 8.0.1 (2024-02-25) ### Bug Fixes * build: correctly output ESM
# 8.0.0 (2024-02-25) ### Features * package is now ESM (#422) (177aacf) ### BREAKING CHANGES * package is now ESM
# 8.0.0-beta.3 (2024-02-25) ### Bug Fixes * build: correctly output ESM
# 8.0.0-beta.2 (2024-02-25) ### Bug Fixes * update deps
# 8.0.0-beta.1 (2024-02-25) ### Bug Fixes * bump to stable deps (93eeff0) ### Features * package is now ESM (9b7135a) ### BREAKING CHANGES * package i
deps: upgrade @octokit/types to v13
deps: update dependency @octokit/types to v12
deps: update octokit monorepo (major)
deps: update octokit monorepo (major)
stop testing against NodeJS v14, v16
Drop support for NodeJS v14, v16
ci: stop testing against NodeJS v14, v16
ci: stop testing against NodeJS v14, v16
ci: stop testing against NodeJS v14, v16
ci: stop testing against NodeJS v14, v16
ci: stop testing against NodeJS v14, v16
Update build.mjs
## 5.0.6 (2023-06-09) ### Bug Fixes * build: switch to esbuild
deps: update dependency @octokit/types to v9
deps: update dependency @octokit/types to v8
deps: update dependency @octokit/request to v6
deps: update dependency @octokit/types to v7
deps: update dependency @octokit/auth-oauth-device to v4
stop testing against NodeJS v10, v12
deps: update dependency @octokit/auth-oauth-user to v2
revert dependency update of @octokit/request (#244) (0e04546), closes #239
deps: update dependency @octokit/request to v6
deps: Bump @octokit/request to track release containing fix for security vulnerability in node-fetch
typescript: export FactoryGitHubWebFlow, FactoryGitHubDeviceFlow
set basic auth from client ID/secret to bump rate limit
deps: remove unused package @octokit/request-error
README: code highlight syntax fix
typescript: OAuthAppAuthInterface, GitHubAuthInterface
delegate OAuth user access usage to @octokit/auth-oauth-user. Add OAuth Device flow and factory auth option
@octokit/auth-oauth-user. Add OAuth Device flow and factory auth option (#164) (92639dc)auth({type: "token"}) is no longer supported. Use auth({type: "oauth-user"}) insteadcode, state, redirectUrl strategy options are no longer supported. Use @octokit/auth-oauth-user insteadauth.hook is no longer supported. Use @octokit/auth-oauth-user insteadREADME: replace deprecated {type: "token"} with {type: "oauth-user"}
deprecate auth({ type: "token" }), code, state, redirectUrl strategy options, and setting user authentication in request hook
## 3.0.8 (2021-01-25) ### Bug Fixes * deps: lock file maintenance
deps: bump @octokit/types from 5.5.0 to 6.0.0
README: replace "cdn.pika.dev" with "cdn.skypack.dev" (77234f3), closes #123 #125
deps: bump universal-user-agent from 5.0.0 to 6.0.0
deps: bump @octokit/types from 4.1.9 to 5.0.0
deps: bump @octokit/types from 2.1.1 to 4.0.1
package: update @octokit/request-error to version 2.0.0
auth.hook: authenticate as app if code strategy option is not set
:client_id and :access_token URL parameters are no longer set by default
:client_id and :access_token URL parameters are no longer set by defaultclient_id and client_secret are now passed as basic authentication for any URLurl option has been removed for auth({ type: "app" })auth({ type: "app" }) no longer returns a .query keypackage: update universal-user-agent to version 5.0.0
new endpoints requiring Basic Authentication
Avoid double requests when retrieving a new token
Allow to pass code/state/redirectUrl to auth()
handle error response with 200 status code from OAuth endpoint
package: update @octokit/types to version 2.0.0
improve TypeScript definitions via @octokit/types
package: version in published package
package: update universal-user-agent to version 4.0.0
Your coding agent can read these notes before it upgrades. Set up the MCP server →