NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1338 most downloaded on npm
One-time password input component for React.
Last release 1 months ago
18 Aug 2026
Ships unpredictably
gaps range from 9 days to 1.6 years
Nearly every release is documented
notes for 6 of 6 stable releases
19 versions withdrawn
withdrawn after publishing
3 years old
26 releases · first in 2024
…which returns in 2.0.0 as a documented breaking change.
Promotes the safe 1.5.0-beta.2 code without functional changes. Everything in this release is backwards-compatible: no public type changes and no behavior changes beyond the bug fixes below. Two beta.1 experiments are deliberately excluded — the iOS native-selection workaround (the thin native selection artifact remains a known cosmetic limitation) and the onComplete type narrowing, which returns in 2.0.0 as a documented breaking change.
ResizeObserver before observing--root-height resolves, preventing iOS focus zoomnonce prop for Content-Security-Policy supportselectionchange listenerSafe release candidate for 1.5.0. This release withdraws the experimental iOS native-selection workaround from 1.5.0-beta.1 after compatibility review. The edit menu, paste, typing, selection and focus behavior return to the proven 1.4.x implementation; the thin native selection artifact remains a known iOS limitation.
It also withdraws the onComplete type narrowing from 1.5.0-beta.1. Although type-level only, it can fail compilation of existing handlers typed with extra or non-string parameters (a common example is passing react-hook-form's handleSubmit(onSubmit) directly), which makes it a breaking change under semver. It will return in 2.0.0 with a documented migration path.
onComplete narrowing from 1.5.0-beta.1, deferring it to 2.0.0Deprecated experimental release. It introduced an iOS native-selection workaround that moved and scaled the underlying input, and narrowed the onComplete type in a way that can break compilation of existing apps. Both were withdrawn in 1.5.0-beta.2 and are not planned for 1.5.0 stable. Existing installs remain reproducible, but new beta users should use 1.5.0-beta.2 or later.
Prepared but not published. Its safe changes are included in 1.5.0-beta.2.
overflow: hidden/clip ancestors, the container itself, and the real viewport width) and skips the push when the gutter doesn't fit; the badge then stays over the last slot, exactly as with pushPasswordManagerStrategy="none". Nothing is ever clipped, so extensions keep rendering their badges.spellCheck now defaults to false; passing your own spellCheck prop still overrides it.ResizeObserver (e.g. iOS Safari <13.4) crashed on mount. When the observer is unavailable, the root height is now simply measured once on mount.--root-height resolves
act() warnings and flaky CI test runs.nonce prop
<style> tag the library injects, so a style-src Content-Security-Policy that requires nonces no longer blocks it.null is not an object (evaluating 'setSelectionRange') crash when the listener fired while the ref was already null.<font> elements), crashing React on the next re-render — easiest to hit with alphanumeric codes under an active page translation. The container now carries translate="no"; a one-time code is never meaningful to translate.:autofill in older Android WebViews, for instance). Nothing breaks when that happens, but the console.error was captured by Sentry and similar tools as if the application had failed. Same message, warning level.onComplete to (value: string) => unknownOne column per month.
…directly), which makes it a breaking change under semver. It will return in 2.0.0 with a documented migration path.
Safe release candidate for 1.5.0. This release withdraws the experimental iOS native-selection workaround from 1.5.0-beta.1 after compatibility review. The edit menu, paste, typing, selection and focus behavior return to the proven 1.4.x implementation; the thin native selection artifact remains a known iOS limitation.
It also withdraws the onComplete type narrowing from 1.5.0-beta.1. Although type-level only, it can fail compilation of existing handlers typed with extra or non-string parameters (a common example is passing react-hook-form's handleSubmit(onSubmit) directly), which makes it a breaking change under semver. It will return in 2.0.0 with a documented migration path.
onComplete narrowing from 1.5.0-beta.1, deferring it to 2.0.0Everything that landed after 1.4.2, in one beta. (A 1.5.0-beta.0 was drafted along the way but never published to npm; its items are folded in below.)
Everything that landed after 1.4.2, in one beta. (A 1.5.0-beta.0 was drafted along the way but never published to npm; its items are folded in below.)
The headline: the iOS native selection artifact — the thin, caret-tall line documented as a known limitation in #32 and reported in #75/#110 — is gone.
::selection, CSS opacity, and ancestor clipping — but it tracks the rendered text geometry. So the text is parked offscreen (text-indent: -9999px) and revealed at the pointer's position only during pointer gestures, because the copy/paste menu can only anchor to an on-screen caret/selection rect. Collapsed letter-spacing keeps the revealed artifact the same size whether 1 or 6 chars are selected, and font-size: 16px + transform: scale(0.1) (with a compensating 10x layout box, so the tap area still exactly matches the container) compresses it to iOS's ~2px minimum painting size without ever dipping below the 16px focus-zoom threshold — no page zoom, no maximum-scale=1 required from apps.@supports (-webkit-touch-callout: none) guard is false on Blink/Gecko/desktop WebKit). iPhone Chrome/Firefox/in-app browsers are WebKit and get the fix.font-size: 16px !important, custom transforms or text-indent on [data-input-otp]), remove those workarounds — overriding the input's geometry can now interfere with the fix.--root-height from the container instead of the input (same value in practice; the input's layout box is enlarged 10x on iOS)/ios-probe (parameterized probe) and /shadcn (faithful reproduction of the shadcn/ui input-otp demo), since the iOS code path cannot be exercised by the Playwright suiteoverflow: hidden/clip ancestors, the container itself, and the real viewport width) and skips the push when the gutter doesn't fit; the badge then stays over the last slot, exactly as with pushPasswordManagerStrategy="none". Nothing is ever clipped, so extensions keep rendering their badges.spellCheck now defaults to false; passing your own spellCheck prop still overrides it.ResizeObserver (e.g. iOS Safari <13.4) crashed on mount. When the observer is unavailable, the root height is now simply measured once on mount.--root-height resolves
act() warnings and flaky CI test runs.nonce prop
<style> tag the library injects, so a style-src Content-Security-Policy that requires nonces no longer blocks it.null is not an object (evaluating 'setSelectionRange') crash when the listener fired while the ref was already null.<font> elements), crashing React on the next re-render — easiest to hit with alphanumeric codes under an active page translation. The container now carries translate="no"; a one-time code is never meaningful to translate.:autofill in older Android WebViews, for instance). Nothing breaks when that happens, but the console.error was captured by Sentry and similar tools as if the application had failed. Same message, warning level.onComplete to (value: string) => unknown
(...args: any[]) => unknown, but the only call site has always passed a single string. Handlers declaring extra parameters (which could never receive values) now fail to compile; every zero-arg or (code: string) handler keeps compiling unchanged.Beta while the iOS fix soaks on real devices. Verified so far on iOS 26.5 (Simulator + manual pass): no artifact at rest, no focus zoom, tap-to-focus, edit menu via double-tap and long-press, paste into full and empty inputs, typing. Still being validated across iOS versions before stable: Select All → Paste from the edit menu, SMS AutoFill from Messages, type-over-when-full, RTL, and iPadOS (Scribble, pointer).
Deprecated experimental release. It introduced an iOS native-selection workaround that moved and scaled the underlying input, and narrowed the onComplete type in a way that can break compilation of existing apps. Both were withdrawn in 1.5.0-beta.2 and are not planned for 1.5.0 stable. Existing installs remain reproducible, but new beta users should use 1.5.0-beta.2 or later.
chore(input): remove unintentional log within internal pasteListener
chore(input): add peer dep for react@19-rc
I'm sorry to skip 1.3.0 due to an issue I've had while publishing the NPM package.
I'm sorry to skip 1.3.0 due to an issue I've had while publishing the NPM package.
REGEXP_ONLY_DIGITS as the default pattern behavior, mistaking mobile users when they couldn't type in or even paste alphanumeric entries.pasteTransformer={pasted => pasted.replaceAll('-','')}.data-input-otp-placeholder-shown when its content is empty.blur event was triggering even if the user hasn't requested it. The sacrifice was to remove the auto re-focus feature for password manager badges, meaning if the password badge ever disappears, then the user himself has to re-trigger focus by manually clicking or selecting the input.Nothing published for this version
chore(input): add peer dep for react@19
fix(input): prevent single caret selection on deletion/cutting
fix(input/css): specify color: transparent !important for ::selection modifier
color: transparent !important for ::selection modifierchore(input): remove experimental flag pushPasswordManagerStrategy
pushPasswordManagerStrategyfix(input): use color not text for autofillStyles
color not text for autofillStyleschore(input): don't restrict inputMode typing
- fix(input): renderfn typing
feat(input): add context option
SelectionTypefeat(input/no-js): allow opting out of no-js fallback
fix(input): immediately update selection after paste
fix(input/firefox): use setselectionrange direction:backwards
No input scope changes for this version.
No input scope changes for this version.
Nothing published for this version
No input scope changes for this version.
No input scope changes for this version.
No input scope changes for this version.
No input scope changes for this version.
Nothing published for this version
chore(input): always focus onContainerClick
Nothing published for this version
fix(input): do not trigger onComplete twice
onComplete twiceYour coding agent can read these notes before it upgrades. Set up the MCP server →