NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #433 most downloaded on npm
JWA, JWS, JWE, JWT, JWK, JWKS for Node.js, Browser, Cloudflare Workers, Deno, Bun, and other Web-interoperable runtimes
Last release 24 days ago
05 Sep 2026
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
106 versions withdrawn
withdrawn after publishing
11 years old
245 releases · first in 2015
Node.js: return Uint8Array (not a Buffer) from base64url.decode
One column per quarter.
add sideEffects:false to nested ESM package.json files
Nothing published for this version
add a workerd package.json target
Nothing published for this version
add a maxOutputLength option to zlib inflate (1b91d88), fixes CVE-2024-28176
types: export GetKeyFunction (#592) (936c9df), closes #591
This release contains only Node.js CITGM related test updates.
This release contains only Node.js CITGM related test updates.
Fixes https://github.com/nodejs/citgm/issues/1011
build: add a node target for jose-browser-runtime releases
resolve missing types for the cryptoRuntime const
export the used crypto runtime as a constant
build: publish bundle and umd files with jose-browser-runtime module (62fcbcc), closes #571
catch type error when decoding base64url signature
cleanup NODE-ED25519 workerd workarounds
Revert "fix(types): headers and payloads may only be JSON values and primitives" (06d8101), closes #534
types: headers and payloads may only be JSON values and primitives
This release is to start using provenance statements.
This release is to start using provenance statements.
add requiredClaims JWT validation option
This release contains only minor code refactoring, documentation, and IntelliSense updates.
This release contains only minor code refactoring, documentation, and IntelliSense updates.
workerd: avoid "The script will never generate a response" edge cases completely (96a8c99), closes #355 #509
types: allow generics to aid in CryptoKey or KeyObject narrowing of KeyLike
types: declare explicit return from EmbeddedJWK
clarify when alg is used and required on key imports
enable key iteration over JWKSMultipleMatchingKeys
const JWKS = jose.createRemoteJWKSet(new URL('https://www.googleapis.com/oauth2/v3/certs'))
const options = {
issuer: 'urn:example:issuer',
audience: 'urn:example:audience',
}
const { payload, protectedHeader } = await jose
.jwtVerify(jwt, JWKS, options)
.catch(async (error) => {
if (error?.code === 'ERR_JWKS_MULTIPLE_MATCHING_KEYS') {
for await (const publicKey of error) {
try {
return await jose.jwtVerify(jwt, publicKey, options)
} catch (innerError) {
if (innerError?.code === 'ERR_JWS_SIGNATURE_VERIFICATION_FAILED') {
continue
}
throw innerError
}
}
throw new jose.errors.JWSSignatureVerificationFailed()
}
throw error
})
console.log(protectedHeader)
console.log(payload)
build: ignore deno files in npm publishes
CF Workers: improve miniflare compat with different Node.js versions, get ready for future non-proprietary support (3406b9f), closes #446 #495 #497
### Refactor * node: dry node version checks
This release contains only code refactoring, documentation updates, and Node.js CITGM related test updates.
This release contains only code refactoring, documentation updates, and Node.js CITGM related test updates.
respect JWK ext for symmetric keys
typo in importPKSC8 error message
v4.10.1, v4.10.2, and v4.10.3 contain only code refactoring, documentation updates, and updates necessary to include jose in the Node.js CITGM builds.
v4.10.1, v4.10.2, and v4.10.3 contain only code refactoring, documentation updates, and updates necessary to include jose in the Node.js CITGM builds.
Nothing published for this version
Nothing published for this version
Curve25519, and Curve448 support for WebCryptoAPI runtimes based on [Secure Curves in the Web Cryptography API][]
update CEK length validation error message
limit default PBES2 alg's computational expense
deno: add a Deno package entrypoint
add support for RFC 9278 - JWK Thumbprint URI
This release contains only code refactoring and documentation updates.
This release contains only code refactoring and documentation updates.
typescript: add types export for nodenext module resolution
add "worker" export in package.json
add createRemoteJWKSet cacheMaxAge option (5017d95), closes #394
dont check JWT iat is in the past unless maxTokenAge is used
This release contains only code refactoring and documentation updates.
This release contains only code refactoring and documentation updates.
mark APIs and parameters that can lead to footguns as deprecated
web api runtime: rely on default fetch init values
decrypting empty ciphertext compact JWEs
typescript: allow synchronous get key functions
concurrent fetch await in cloudflare (e44cd18), closes #355
add createLocalJWKSet, resolver to verify using a local JWKSet
only add y to the epk header parameter when EC keys are used (dd6775e), closes #348
This release contains only code refactoring and documentation updates.
This release contains only code refactoring and documentation updates.
typescript: b64: true is fine to use in JWT, its useless, but allowed
electron: rsa-pss keys are never supported
typescript: b64 header regression
Compact JWS verification handles a zero-length payload string
typescript: apply updated compact and jwt headers to compact/jwt verify and decrypt results
createRemoteJWKSet handles all JWS syntaxes
add GeneralSign signature and GeneralEncrypt recipient builder chaining
node: dont mention CryptoKey in versions without webcrypto
Your coding agent can read these notes before it upgrades. Set up the MCP server →