NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #433 most downloaded on npm
JWA, JWS, JWE, JWT, JWK, JWKS for Node.js, Browser, Cloudflare Workers, Deno, Bun, and other Web-interoperable runtimes
Last release 29 days ago
05 Sep 2026
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
106 versions withdrawn
withdrawn after publishing
11 years old
245 releases · first in 2015
clarify and shorten public API guidance
One column per quarter.
render subpath indexes as tables
jose: consume serialization members once
types: undeprecate PBES2 p2c parameter
enforce a single recipient when decrypting dir and ECDH-ES
require own JOSE properties for presence checks
types: accept host CryptoKey declarations
compare claim values for falsy validation options
update README.md and SECURITY.md to reflect passed EOL dates
cleanly reject invalid PBES2 p2c
reject failed decompression with JWEInvalid error
reorganize internals, less files, smaller footprint
re-introduce JWE "zip" (Compression Algorithm) Header Parameter support
avoid export * as for google closure's compiler sake (6303d98), closes #832
remove mention of Edge Runtime from the readme
support AKP JWKs in calculateJwkThumbprint and calculateJwkThumbprintUri
### Refactor * more readability in ecdhes.ts (84da9de) * update asn1.ts helpers
add known caveats to customFetch
typ checking edge-cases when it contains a slash (/) character
### Refactor * removed unused claims methods (74719cf) * reorganize jwt claim set utils
add more symbol document, ignore ts-private fields
export [customFetch] symbol from the default entrypoint (1615614), closes #762
improve generate key/secret and import function descriptions
add various exported symbol descriptions
types: make JWKParameters.kty compatible with @types/node and @types/web
optimize base64 with tc39/proposal-arraybuffer-base64 (8a0da69), closes #752
remove root module tag so that README.md shows up on jsr.io
add module tags to all entrypoints
types: update build to include extensions in type imports
removed deprecated experimental APIs
support fully specified Ed25519 algorithm identifier
Revert "refactor(build): simplify package exports"
build: simplify package exports
types: update error definitions
use as Type for type assertions instead of \
types: remove index signatures from JWK interfaces
types: add missing index signature on the convenience JWK types
allow JWK objects as "key" input to sign and verify
This method of passing private or public keys does not yield the same performance as passing a CryptoKey or KeyObject instances, its main purpose is for convenience or for when you're not going to be re-using the same set of keys for the operation, in which case you should use one of the import key methods to obtain a CryptoKey or KeyObject.
const alg = "RS256";
const jwk = {
kty: "RSA",
n: "whYOFK2Ocbbpb_zVypi9SeKiNUqKQH0zTKN1-6fpCTu6ZalGI82s7XK3tan4dJt90ptUPKD2zvxqTzFNfx4HHHsrYCf2-FMLn1VTJfQazA2BvJqAwcpW1bqRUEty8tS_Yv4hRvWfQPcc2Gc3-_fQOOW57zVy-rNoJc744kb30NjQxdGp03J2S3GLQu7oKtSDDPooQHD38PEMNnITf0pj-KgDPjymkMGoJlO3aKppsjfbt_AH6GGdRghYRLOUwQU-h-ofWHR3lbYiKtXPn5dN24kiHy61e3VAQ9_YAZlwXC_99GGtw_NpghFAuM4P1JDn0DppJldy3PGFC0GfBCZASw",
e: "AQAB",
d: "VuVE_KEP6323WjpbBdAIv7HGahGrgGANvbxZsIhm34lsVOPK0XDegZkhAybMZHjRhp-gwVxX5ChC-J3cUpOBH5FNxElgW6HizD2Jcq6t6LoLYgPSrfEHm71iHg8JsgrqfUnGYFzMJmv88C6WdCtpgG_qJV1K00_Ly1G1QKoBffEs-v4fAMJrCbUdCz1qWto-PU-HLMEo-krfEpGgcmtZeRlDADh8cETMQlgQfQX2VWq_aAP4a1SXmo-j0cvRU4W5Fj0RVwNesIpetX2ZFz4p_JmB5sWFEj_fC7h5z2lq-6Bme2T3BHtXkIxoBW0_pYVnASC8P2puO5FnVxDmWuHDYQ",
p: "07rgXd_tLUhVRF_g1OaqRZh5uZ8hiLWUSU0vu9coOaQcatSqjQlIwLW8UdKv_38GrmpIfgcEVQjzq6rFBowUm9zWBO9Eq6enpasYJBOeD8EMeDK-nsST57HjPVOCvoVC5ZX-cozPXna3iRNZ1TVYBY3smn0IaxysIK-zxESf4pM",
q: "6qrE9TPhCS5iNR7QrKThunLu6t4H_8CkYRPLbvOIt2MgZyPLiZCsvdkTVSOX76QQEXt7Y0nTNua69q3K3Jhf-YOkPSJsWTxgrfOnjoDvRKzbW3OExIMm7D99fVBODuNWinjYgUwGSqGAsb_3TKhtI-Gr5ls3fn6B6oEjVL0dpmk",
dp: "mHqjrFdgelT2OyiFRS3dAAPf3cLxJoAGC4gP0UoQyPocEP-Y17sQ7t-ygIanguubBy65iDFLeGXa_g0cmSt2iAzRAHrDzI8P1-pQl2KdWSEg9ssspjBRh_F_AiJLLSPRWn_b3-jySkhawtfxwO8Kte1QsK1My765Y0zFvJnjPws",
dq: "KmjaV4YcsVAUp4z-IXVa5htHWmLuByaFjpXJOjABEUN0467wZdgjn9vPRp-8Ia8AyGgMkJES_uUL_PDDrMJM9gb4c6P4-NeUkVtreLGMjFjA-_IQmIMrUZ7XywHsWXx0c2oLlrJqoKo3W-hZhR0bPFTYgDUT_mRWjk7wV6wl46E",
qi: "iYltkV_4PmQDfZfGFpzn2UtYEKyhy-9t3Vy8Mw2VHLAADKGwJvVK5ficQAr2atIF1-agXY2bd6KV-w52zR8rmZfTr0gobzYIyqHczOm13t7uXJv2WygY7QEC2OGjdxa2Fr9RnvS99ozMa5nomZBqTqT7z5QV33czjPRCjvg6FcE",
};
const jwt = await new jose.SignJWT({ "urn:example:claim": true })
.setProtectedHeader({ alg })
.setIssuedAt()
.setIssuer("urn:example:issuer")
.setAudience("urn:example:audience")
.setExpirationTime("2h")
.sign(jwk);
console.log(jwt);
const alg = "RS256";
const jwk = {
kty: "RSA",
n: "whYOFK2Ocbbpb_zVypi9SeKiNUqKQH0zTKN1-6fpCTu6ZalGI82s7XK3tan4dJt90ptUPKD2zvxqTzFNfx4HHHsrYCf2-FMLn1VTJfQazA2BvJqAwcpW1bqRUEty8tS_Yv4hRvWfQPcc2Gc3-_fQOOW57zVy-rNoJc744kb30NjQxdGp03J2S3GLQu7oKtSDDPooQHD38PEMNnITf0pj-KgDPjymkMGoJlO3aKppsjfbt_AH6GGdRghYRLOUwQU-h-ofWHR3lbYiKtXPn5dN24kiHy61e3VAQ9_YAZlwXC_99GGtw_NpghFAuM4P1JDn0DppJldy3PGFC0GfBCZASw",
e: "AQAB",
};
const jwt =
"eyJhbGciOiJSUzI1NiJ9.eyJ1cm46ZXhhbXBsZTpjbGFpbSI6dHJ1ZSwiaWF0IjoxNjY5MDU2NDg4LCJpc3MiOiJ1cm46ZXhhbXBsZTppc3N1ZXIiLCJhdWQiOiJ1cm46ZXhhbXBsZTphdWRpZW5jZSJ9.gXrPZ3yM_60dMXGE69dusbpzYASNA-XIOwsb5D5xYnSxyj6_D6OR_uR_1vqhUm4AxZxcrH1_-XJAve9HCw8az_QzHcN-nETt-v6stCsYrn6Bv1YOc-mSJRZ8ll57KVqLbCIbjKwerNX5r2_Qg2TwmJzQdRs-AQDhy-s_DlJd8ql6wR4n-kDZpar-pwIvz4fFIN0Fj57SXpAbLrV6Eo4Byzl0xFD8qEYEpBwjrMMfxCZXTlAVhAq6KCoGlDTwWuExps342-0UErEtyIqDnDGcrfNWiUsoo8j-29IpKd-w9-C388u-ChCxoHz--H8WmMSZzx3zTXsZ5lXLZ9IKfanDKg";
const { payload, protectedHeader } = await jose.jwtVerify(jwt, jwk, {
issuer: "urn:example:issuer",
audience: "urn:example:audience",
});
console.log(protectedHeader);
console.log(payload);
omit LocalJWKSet export since it's no longer needed for RemoteJWKSet
graduate jwksCache to stable API
add sideEffects:false to nested ESM package.json files
CryptoKey normalization is not always async
normalize is always defined for Web API runtimes
support KeyObject inputs in WebCryptoAPI runtimes given compatibility
ensure latest release on npm is v5.x
expose JWT's payload in JWTClaimValidationFailed instances (58bcffb), closes #680
allow observing remote JWKS resolver state and its manual reload
use createLocalJWKSet instead of LocalJWKSet in createRemoteJWKSet
move iv generation and optional outputs around
types: iv and tag is optional in JSON serializations
build: refactor export targets for browser, node cjs, and node esm builds
extend JWT NumericDate setter syntax
add errors and base64url submodule exports
do not mutate JWTVerifyOptions.requiredClaims (1bf9cec), closes #610
deprecate the RSA1_5 JWE Algorithm
add payload generics to jose.decodeJwt (9de49e2), closes #604
createRemoteJWKSet: ensure a default user-agent header is present (887dd3c), closes #600
also use ES2020 in the CDN bundles
Your coding agent can read these notes before it upgrades. Set up the MCP server →