NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #904 most downloaded on npm
JSON Web Token implementation (symmetric and asymmetric)
Last release 10 months ago
04 Dec 2025
Ships unpredictably
gaps range from 2 weeks to 3.8 years
Most releases are documented
notes for 50 of 58 stable releases
24 versions withdrawn
withdrawn after publishing
13 years old
82 releases · first in 2013
Co-authored-by: Frederik Prijck frederik.prijck@okta.com
Create test.yml
Delete .circleci directory
Update test.yml
bump jws to version 4.0.1
update CI workflows
chore: fixing test command
Co-authored-by: Frederik Prijck frederik.prijck@okta.com
Release 9.0.2
Release 9.0.2 (#935)
One column per quarter.
Updating package version to 9.0.1
Updating package version to 9.0.1 (#920)
Check if node version supports asymmetricKeyDetails
Check if node version supports asymmetricKeyDetails
Validate algorithms for ec key type
Rename variable
Rename function
Add early return for symmetric keys
Validate algorithm for RSA key type
Validate algorithm for RSA-PSS key type
Check key types for EdDSA algorithm
Rename function
Move validateKey function to module
Convert arrow to function notation
Validate key in verify function
Simplify if
Convert if to switch..case
Guard against empty key in validation
Remove empty line
Add lib to check modulus length
Add modulus length checks
Validate mgf1HashAlgorithm and saltLength
Check node version before using key details API
Use built-in modulus length getter
Fix Node version validations
Remove duplicate validateKey
Add periods to error messages
Fix validation in verify function
Make asymmetric key validation the latest validation step
Change key curve validation
Remove support for ES256K
Fix old test that was using wrong key types to sign tokens
Enable RSA-PSS for old Node versions
Add specific RSA-PSS validations on Node 16 LTS+
Improve error message
Simplify key validation code
Fix typo
Improve error message
Change var to const in test
Change const to let to avoid reassigning problem
Improve error message
Test incorrect private key type
Rename invalid to unsupported
Test verifying of jwt token with unsupported key
Test invalid private key type
Change order of object parameters
Move validation test to separate file
Move all validation tests to separate file
Add prime256v1 ec key
Remove modulus length check
WIP: Add EC key validation tests
Fix node version checks
Fix error message check on test
Add successful tests for EC curve check
Remove only from describe
Remove only
Remove duplicate block of code
Move variable to a different scope and make it const
Convert allowed curves to object for faster lookup
Rename variable
Change variable assignment order
Remove unused object properties
Test RSA-PSS happy path and wrong length
Add missing tests
Pass validation if no algorithm has been provided
Test validation of invalid salt length
Test error when signing token with invalid key
Change var to const/let in verify tests
Test verifying token with invalid key
Improve test error messages
Add parameter to skip private key validation
Replace DSA key with a 4096 bit long key
Test allowInvalidPrivateKeys in key signing
Improve test message
Rename variable
Add key validation flag tests
Fix variable name in Readme
Change private to public dsa key in verify
Rename flag
Run EC validation tests conditionally
Fix tests in old node versions
Ignore block of code from test coverage
Separate EC validations tests into two different ones
Add comment
Wrap switch in if instead of having an early return
Remove unsupported algorithms from asymmetric key validation
Rename option to allowInvalidAsymmetricKeyTypes and improve Readme
9.0.0
adding migration notes to readme
adding changelog for version 9.0.0
Co-authored-by: julienwoll julien.wollscheid@auth0.com
Breaking changes: See Migration from v8 to v9
Arbitrary File Write via verify function - CVE-2022-23529Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541Unrestricted key type could lead to legacy keys usage - CVE-2022-23539fix: ensure correct PS signing and verification (#585) (e5874ae428ffc0465e6bd4e660f89f78b56a74a6), closes #585
feat: add PS JWA support for applicable node versions (#573) (eefb9d9c6eec54718fa6e41306bda84788df7bec), closes #573
Add verify option for nonce validation (#540) (e7938f06fdf2ed3aa88745b72b8ae4ee66c2d0d0), closes #540
docs: add some clarifications (#473) (cd33cc81f06068b9df6c224d300dc6f70d8904ab), closes #473
security: deps: jws@3.1.5 (#477) (ebde9b7cc75cb7ab5176de7ebc4a1d6a8f05bd51), closes #465
bug fix: Check payload is not null when decoded.
- Add a new mutatePayload option
ci: add newer node versions to build matrix
Enhance audience check to verify against regular expressions
Remove lodash.isarray dependency
lodash.isarray dependency (#394) (7508e8957cb1c778f72fa9a363a7b135b3c9c36d)Breaking changes: See [Migration notes from v7]
Breaking changes: See Migration notes from v7
Fix breaking change on 7.4.2 for empty secret + "none" algorithm (sync code style) (PR 386)
bugfix: sign: add check to be sure secret has a value
bump ms to v2 due a ReDoS vulnerability
Add docs about numeric date fields
Add more information to maxAge option in README
maxAge option in README (1b0592e99cc8def293eed177e2575fa7f1cf7aa5)clockTimestamp option to verify() you can set the current time in seconds with it (#274) (8fdc1504f4325e7003894ffea078da9cba5208d9)verify() input (#305) (1b6ec8d466504f58c5a6e2dae3360c828bad92fb), closes #305add nsp check to find vulnerabilities on npm test
improve the documentation for expiration
keyid on sign. (b412be91b89acb3a742bb609d3b54e47e1dfc441)improve the documentation for expiration
Revert "Merge branch 'venatir-master'"
Fixed tests, however typ: 'JWT' should not be in the options at all, so please review other tests
Use lodash.once instead of unlicensed/unmaintained cb
fix issue with buffer payload. closes #216 (6b50ff324b4dfd2cb0e49b666f14a6672d015b22), closes #216
- update jws in package.json
Nothing published for this version
do not mutate options in jwt.verify, closes #227 (63263a28a268624dab0927b9ad86fffa44a10f84), closes #227
Exp calculated based on iat. fix #217 (757a16e0e35ad19f9e456820f55d5d9f3fc76aee), closes #217
Nothing published for this version
change jwt.sign to return errors on callback instead of throwing errors
add support for options.clockTolerance to jwt.verify
options.clockTolerance to jwt.verify (65ddea934f226bf06bc9d6a55be9587515cfc38d)fix sign method for node.js 0.12. closes #193 (9c38374142d3929be3c9314b5e9bc5d963c5955f), closes #193
Nothing published for this version
- verify unsigned tokens
This was an immediate change after publishing 6.0.0.
This was an immediate change after publishing 6.0.0.
expiresInMinutes and expiresInSeconds are deprecated and no longer supported.
Change .sign to standard async callback (50873c7d45d2733244d5da8afef3d1872e657a60)
Improved the options for the sign method (53c3987b3cc34e95eb396b26fc9b051276e2f6f9)
expiresIn when the payload is not an object (304f1b33075f79ed66f784e27dc4f5307aa39e27)expiresInMinutes and expiresInSeconds are deprecated and no longer supported.notBeforeInMinutes and notBeforeInSeconds are deprecated and no longer supported.options are strongly validated.options.expiresIn, options.notBefore, options.audience, options.issuer, options.subject and options.jwtid are mutually exclusive with payload.exp, payload.nbf, payload.aud, payload.issoptions.algorithm is properly validated.options.headers is renamed to options.header.update CHANGELOG to reflect most of the changes. closes #136 (b87a1a8d2e2533fbfab518765a54f00077918eb7), closes #136
update readme (53a88ecf4494e30e1d62a1cf3cc354650349f486)
add support for validating multiples issuers. closes #163 (39d9309ae05648dbd72e5fd1993df064ad0e8fa5), closes #163
Nothing published for this version
added missing validations of sub and jti
- minor
add a console.warn on invalid options for string payloads
fix signing method with sealed objects, do not modify the params object. closes #147 (be9c09af83b09c9e72da8b2c6166fa51d92aeab6), closes #147
fix nbf verification. fix #152 (786d37b299c67771b5e71a2ca476666ab0f97d98), closes #152
improvements to nbf and jti claims
Nothing published for this version
deprecate expireInMinutes and expireInSeconds - in favor of expiresIn
Nothing published for this version
Nothing published for this version
- added async signing (9414fbcb15a1f9cf4fe147d070e9424c547dabba) - Update README.md
add note to explain, related to #96 #101 #6
Nothing published for this version
Added support for subject and jwt id
this referring to the global object instead of module.exports in verify() (93f554312e37129027fcf4916f48cb8d1b53588c)fix typo in docs . closes #86 (3d3413221f36acef4dfd1cbed87f1f3565cd6f84), closes #86
Add option to return header and payload when decoding.
> Important: versions >= 4.2.2 this library are safe to use but we decided to deprecate everything < 5.0.0 to prevent security warnings from library n…
iat if the user does not specify that argument.https://github.com/auth0/node-jsonwebtoken/commit/e900282a8d2dff1d4dec815f7e6aa7782e867d91 https://github.com/auth0/node-jsonwebtoken/commit/35036b188b4ee6b42df553bbb93bc8a6b19eae9d https://github.com/auth0/node-jsonwebtoken/commit/954bd7a312934f03036b6bb6f00edd41f29e54d9 https://github.com/auth0/node-jsonwebtoken/commit/24a370080e0b75f11d4717cd2b11b2949d95fc2e https://github.com/auth0/node-jsonwebtoken/commit/a77df6d49d4ec688dfd0a1cc723586bffe753516
header.alg mismatch exception to invalid algorithm and adding more mismatch tests.As jws@3.0.0 changed the verify method signature to be jws.verify(signature, algorithm, secretOrKey), the token header must be decoded first in order to make sure that the alg field matches one of the allowed options.algorithms. After that, the now validated header.alg is passed to jws.verify
As the order of steps has changed, the error that was thrown when the JWT was invalid is no longer the jws one:
{ [Error: Invalid token: no header in signature 'a.b.c'] code: 'MISSING_HEADER', signature: 'a.b.c' }
That old error (removed from jws) has been replaced by a JsonWebTokenError with message invalid token.
Important: versions >= 4.2.2 this library are safe to use but we decided to deprecate everything
< 5.0.0to prevent security warnings from librarynode-jwswhen doingnpm install.
https://github.com/auth0/node-jsonwebtoken/commit/634b8ed0ff5267dc25da5c808634208af109824e https://github.com/auth0/node-jsonwebtoken/commit/9f24ffd5791febb449d4d03ff58d7807da9b9b7e https://github.com/auth0/node-jsonwebtoken/commit/19e6cc6a1f2fd90356f89b074223b9665f2aa8a2 https://github.com/auth0/node-jsonwebtoken/commit/1e4623420159c6410616f02a44ed240f176287a9 https://github.com/auth0/node-jsonwebtoken/commit/954bd7a312934f03036b6bb6f00edd41f29e54d9 https://github.com/auth0/node-jsonwebtoken/commit/24a370080e0b75f11d4717cd2b11b2949d95fc2e https://github.com/auth0/node-jsonwebtoken/commit/a77df6d49d4ec688dfd0a1cc723586bffe753516
[asymmetric-keys] Fix verify for RSAPublicKey formated keys (jfromaniello - awlayton) https://github.com/auth0/node-jsonwebtoken/commit/402794663b9521
jfromaniello - awlayton)
https://github.com/auth0/node-jsonwebtoken/commit/402794663b9521bf602fcc6f2e811e7d3912f9dc
https://github.com/auth0/node-jsonwebtoken/commit/8df6aabbc7e1114c8fb3917931078254eb52c222[asymmetric-keys] Fixed issue when public key starts with BEING PUBLIC KEY (https://github.com/auth0/node-jsonwebtoken/issues/70) (jfromaniello) https
jfromaniello)
https://github.com/auth0/node-jsonwebtoken/commit/7017e74db9b194448ff488b3e16468ada60c4ee5Your coding agent can read these notes before it upgrades. Set up the MCP server →