NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2336 most downloaded on npm
Runtime OIDC helpers intended for use with Vercel Functions
Last release 2 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 34 of 34 stable releases
Nothing withdrawn
no release was ever pulled
1 years old
35 releases · first in 2025
One column per month.
ec76b68: Read the Vercel OIDC token from the file specified by VERCEL_OIDC_TOKEN_FILE on each call.
VERCEL_OIDC_TOKEN_FILE on each call.### Patch Changes - Updated dependencies [85cfdc3] - @vercel/cli-config@0.3.1
### Patch Changes - Updated dependencies [c610f14] - @vercel/cli-config@0.3.0
### Patch Changes - Updated dependencies [c4c4f3f] - @vercel/cli-config@0.2.7
### Patch Changes - Updated dependencies [55e8d1e] - @vercel/cli-config@0.2.6
### Patch Changes - Updated dependencies [38a4acd] - @vercel/cli-config@0.2.5
### Patch Changes - Updated dependencies [7a3a2ef] - @vercel/cli-config@0.2.4
2da7809: Remove redundant and ineffective package tests.
### Patch Changes - Updated dependencies [92dfd87] - @vercel/cli-config@0.2.3
6d7fbfa: Bump all workspace packages to trigger a full publish from vercel-internal.
### Patch Changes - Updated dependencies [6e29745] - @vercel/cli-config@0.2.1
d29a8f9: Cache exchanged OIDC tokens in memory, keyed by a hash of the source token, audience, and jti, so repeated exchanges reuse the result instead
skipCache option (surfaced as skipTokenCache on awsCredentialsProvider) to bypass the cache. jti and the cache-skip flags are now only accepted alongside an audience, since they only take effect during a token exchange.fb93ff6: Deprecate getVercelOidcTokenSync in favor of getVercelOidcToken
getVercelOidcTokenSync in favor of getVercelOidcToken415fde0: Add optional audience and jti parameters to exchange Vercel OIDC tokens for use with AWS STS and other providers.
audience and jti parameters to exchange Vercel OIDC tokens for use with AWS STS and other providers.### Patch Changes - Updated dependencies [3f21605] - @vercel/cli-exec@1.0.0
01cf6c2: Add verifyVercelOidcToken for verifying Vercel OIDC tokens against Vercel's remote JWKS.
verifyVercelOidcToken for verifying Vercel OIDC tokens against Vercel's remote JWKS.fddeb55: Add configurable credentials storage handling across the CLI auth stack. Storage of credentials can be configured by the new credStorage key
fddeb55: Add configurable credentials storage handling across the CLI auth stack. Storage of credentials can be configured by the new credStorage key in global config.json or the new VERCEL_TOKEN_STORAGE environment variable. The environment variable takes precedence over the configuration key. Accepted values are file (store credentials in auth.json), keyring (store credentials in system keyring, e.g macOS Keychain or Secrets Service on Linux), and auto (try storing in keyring if available, fall back to file if keyring is not available).
@vercel/oidc supports keyring-stored authentication credentials by delegating the OIDC minting to the CLI executable via @vercel/cli-exec.
5a700dc: Add conditional edge-light export to support Edge Runtime
ae20217: Upgrade to TypeScript 5.9
c56f851: Upgrade to TypeScript 5.9
bf07448: Revert "auth: Make it possible to store CLI credentials in OS keychain (#16083)"
24686d0: Add configurable auth token storage with keyring-backed persistence and file fallback support.
Nothing published for this version
Pin typedoc-plugin-markdown to 3.15.2 and typedoc-plugin-mdn-links to 3.0.3 to match the version used by @vercel/edge. The previous 4.1.2 version requ
typedoc-plugin-markdown to 3.15.2 and typedoc-plugin-mdn-links to 3.0.3 to match the version used by @vercel/edge. The previous 4.1.2 version requires typedoc@0.26.x as a peer dependency but was paired with typedoc@0.24.6, which caused CI failures whenever pnpm hoisted the 4.x plugin (the plugin calls app.internationalization.addTranslations, which does not exist in typedoc 0.24). The choice of which plugin version got hoisted was non-deterministic, which is why the failure appeared as flaky Build @vercel/<pkg> steps in CI. (#16072)- Add optional team and project parameters to getVercelOidcToken() to allow explicit control over token refresh behavior instead of always reading fro
team and project parameters to getVercelOidcToken() to allow explicit control over token refresh behavior instead of always reading from .vercel/project.json (#14864)expirationBufferMs option to both getVercelOidcToken() and getVercelToken() to proactively refresh tokens before they expire (useful for avoiding auth errors mid-request)getVercelToken() function with GetVercelTokenOptions interface to allow refreshing CLI tokens with configurable expiration bufferAllow vercel/oidc to refresh the vercel CLI auth token when running locally
### Patch Changes - Fix OIDC token expiry check
Fix directory permissions so that files can be created under the OIDC data directory in linux
fix(oidc): add "workflow" as export condition
"workflow" as export condition (#14103)fix(oidc): add "react-native" as export condition
"react-native" as export condition (#14066)feat(oidc): export getContext() method
feat(oidc): export getContext() method (#14027)
feat(oidc): add conditional export for browsers (#14027)
Introduces a browser export with mock methods that don't require access to a file system or environment variables. This makes @vercel/oidc usable for universal libraries that are run in both frontend and backend.
fix(oidc): remove ms dependency (#14027)
Drop Node.js 18, bump minimum to Node.js 20
fix "Cannot find module" error caused by dynamically importing files without their extensions
Fix package versions for oidc-aws-credentials-provider, vercel/functions, and publish the next version of vercel/oidc
@vercel/functions re-exports the new functions as deprecated to maintain backwards compatibility.
Your coding agent can read these notes before it upgrades. Set up the MCP server →