NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #433 most downloaded on npm
JWA, JWS, JWE, JWT, JWK, JWKS for Node.js, Browser, Cloudflare Workers, Deno, Bun, and other Web-interoperable runtimes
Last release 26 days ago
05 Sep 2026
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
106 versions withdrawn
withdrawn after publishing
11 years old
245 releases · first in 2015
```js import * as jose from "jose";
example Usage
import * as jose from "jose";
const firstRecipientKeyPair = await jose.generateKeyPair("RSA-OAEP-256");
const secondRecipientKeyPair = await jose.generateKeyPair("ECDH-ES+A256KW");
const thirdRecipientSecret = await jose.generateSecret("A256GCMKW");
const encoder = new TextEncoder();
const plaintext = encoder.encode(
"It’s a dangerous business, Frodo, going out your door."
);
const additionalAuthenticatedData = encoder.encode(
"The Fellowship of the Ring"
);
const enc = new jose.GeneralEncrypt(plaintext)
.setAdditionalAuthenticatedData(additionalAuthenticatedData)
.setProtectedHeader({ enc: "A256GCM" });
enc
.addRecipient(firstRecipientKeyPair.publicKey)
.setUnprotectedHeader({ alg: "RSA-OAEP-256" });
enc
.addRecipient(secondRecipientKeyPair.publicKey)
.setUnprotectedHeader({ alg: "ECDH-ES+A256KW" });
enc
.addRecipient(thirdRecipientSecret)
.setUnprotectedHeader({ alg: "A256GCMKW" });
const jwe = await enc.encrypt();
console.log(JSON.stringify(jwe, null, 4));
for (const recipientKey of [
firstRecipientKeyPair.privateKey,
secondRecipientKeyPair.privateKey,
thirdRecipientSecret,
]) {
await jose.generalDecrypt(jwe, recipientKey);
}
One column per quarter.
importX509 certificate values that do not include a version number (51a18b6), closes #308
### Fixes * allow shorter HMAC secrets
edge-functions: don't use globalThis
build: ensure cjs/esm specific packages have the right main entry
typescript: work around potentially missing global URL from DOM lib (7ed731c), closes #295
web: publish umd and bundle files to cdnjs.com
web: check Uint8Array CEK lengths, refactor for better tree-shaking
web: checking cryptokey applicability early
### Bug Fixes * typescript: export ProduceJWT
typescript: re-export all types from index.d.ts
The deprecated jose/jwk/parse module was removed, use import { importJWK } from 'jose' instead.
import { jwtVerify } from 'jose/jwt/verify' is now just import { jwtVerify } from 'jose'.jose/util/random was removed.jose/jwk/thumbprint named export is renamed to calculateJwkThumbprint, now import { calculateJwkThumbprint } from 'jose'jose/jwk/parse module was removed, use import { importJWK } from 'jose' instead.jose/jwk/from_key_like module was removed, use import { exportJWK } from 'jose' instead.Migrating from v3.x to v4.x is very straight forward.
import statements, require(), or import() invocations should be changed to use just 'jose' as the target.jose dist files for jest, typescript, or other tooling should be removed// before (v3.x)
import { jwtVerify } from 'jose/jwt/verify'
import { SignJWT } from 'jose/jwt/sign'
import * as errors from 'jose/util/errors'
// after (v4.x)
import { jwtVerify, SignJWT, errors } from 'jose'
import { jwtVerify } from 'jose/jwt/verify'
is now just import { jwtVerify } from 'jose'.jose/util/random was removed.jose/jwk/thumbprint named export
is renamed to calculateJwkThumbprint, now
import { calculateJwkThumbprint } from 'jose'jose/jwk/parse module was
removed, use import { importJWK } from 'jose' instead.jose/jwk/from_key_like module was
removed, use import { exportJWK } from 'jose' instead.limit default PBES2 alg's computational expense
remove clutter when tree shaking browser dist
### Bug Fixes * allow tree-shaking of errors
typescript: PEM import functions always resolve a KeyLike, never a Uint8Array
improve key input type errors, remove dependency on @types/node
return resolved key when verify and decrypt resolve functions are used
add X.509/SPKI/PKCS8 key import and SPKI/PKCS8 export functions
cloudflare workers: add support for EdDSA using Ed25519
guard Sign payloads and Encrypt plaintext argument types
node: support rsa-pss keys in Node.js >= 16.9.0 for sign/verify
omit some fetch options when running in Cloudflare Workers env (ced065a), closes #255
deno: ignore incomplete webcrypto api type errors
experimental Deno build & publish
Nothing published for this version
typescript: remove file extensions from types//*.d.ts files (0c432e5), closes #222
experimental Deno build & publish
throw JWEInvalid when jwe protected header is invalid
### Bug Fixes * docs: update doc links again
### Bug Fixes * docs: update doc links
typescript: export generate key pair result interface
add verbose key type error messages
typescript: export consume module interface types
browser: remove the use of a node std-lib in decodeProtectedHeader (d9d4a5f), closes #206
node: use util.types.is* helpers when available
browser: avoid global-conflicting variable name fetch
webcrypto: allow generate* modules extractable: false override
swallow promisified crypto.verify errors
isObject helper in different vm contexts or jest re-assigned globals (7819df7), closes #178
defer AES CBC w/ HMAC decryption after tag verification passes (579485c), fixes CVE-2021-29443, CVE-2021-29444 , CVE-2021-29445, and CVE-2021-29446
node: check CryptoKey algorithm & usage before exporting KeyObject
assert KeyLike input types, change "any" types to "unknown"
node: crypto.verify callback invocation with a private keyobject
export error codes as static properties (89d8003), closes #170
node: use libuv threadpool to sign in node >= 15.12.0
add named exports for all modules
publish alternative Node.js and Browser specific distributions
swallow invalid signature encoding errors
electron >=12.0.0 is now supported (and tested on ci)
typescript: update maxTokenAge type and examples
node runtime json fetch handles connection errors properly
allow CryptoKey instances in a regular non-webcrypto node runtime
export package.json (8c29107), closes #157
workaround downstream dependency issues messing with http (2e58005), closes #154
use 'base64url' encoding when available in Node.js runtime
workaround for RangeError in browser runtime base64url
Nothing published for this version
added JWE General JSON Serialization decryption
added JWS General JSON Serialization signing (6fb862c), closes #129
Your coding agent can read these notes before it upgrades. Set up the MCP server →