NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2466 most downloaded on npm
Library to retrieve RSA public keys from a JWKS endpoint
Last release 3 months ago
19 Jun 2026
Release timing varies
gaps range from 2 weeks to 1.4 years
Nearly every release is documented
notes for 42 of 46 stable releases
1 version withdrawn
withdrawn after publishing
10 years old
47 releases · first in 2016
feat: add cacheMaxAgeFallback and onStaleCacheFallback for graceful JWKS degradation during outages #502 ( cschetan77 )
Added
Added
chore: update lru-memoizer to v3 #476 ( isidrok )
One column per quarter.
feat: upgrade jose dependency to v6 #486 ( cschetan77 )
⚠️ BREAKING CHANGES
⚠️ BREAKING CHANGES
require(esm) support - Loading ECMAScript modules using require(). Non-standard module runtimes such as Jest (uses vm.Script) that do not support this feature may fail while loading ESM. See #493 for details.fix: jwksUri should be optional when custom fetcher is provided #477 ( cschetan77 )
Fixed
Fixed
docs: Add Ask DeepWiki badge to README #445 ( arpit-jn )
Added
Fixed
Bump express from 4.18.2 to 4.19.2 #408 ( dependabot[bot] )
Changed
Fixed
feat: resolve bun/deno compat issues #374 ( panva )
update types/jsonwebtoken update v9.0.0 #349 ( ToshihitoKon )
Fixed
This release drops support for Node 10 and 12
Fix GetVerificationKey typing to include undefined \#329 (AaronMoat)
Type definitions depend on jsonwebtoken \#314 (adamjmcgrath)
Fixed
Fix issue with ES Express import \#310 (adamjmcgrath)
Fixed
fix: express build error \#304 (blindperson)
Fixed
fix: types-compabitility for express-jwt @ 7 \#301 (carboneater)
Fixed
add support for express-jwt@7 \#297 (jfromaniello)
Destroy the request when reaches the timeout (#270) \#271 (amrsalama)
Fixed
[SDK-2626] getKeysInterceptor types \#251 (davidpatrick)
Fixed
Fix retrieveSigningKeys error \#242 (davidpatrick)
Fixed
Security
Interceptor bind client \#237 (erikfried)
Callback backwards compatbility for getSigningKey \#227 (davidpatrick)
Added
getSigningKey #227 (davidpatrick)Fixed
Please take note of the breaking changes and the migration guide below.
With version 2 we have added full JWK/JWS support, bumped Node version support to minimum 10, removed Axios, and exposed a fetcher option to allow user's to completely override how the request to the jwksUri endpoint is made.
Please take note of the breaking changes and the migration guide below.
Added
Changed
The proxy option has been removed from the JwksClient. Support for it was a little spotty through Axios, and we wanted to allow users to have more control over the flow. Now you can specify your proxy by overriding the requestAgent used with an agent with built-in proxy support, or by completely overriding the request library with the fetcher option.
// OLD
const oldClient = jwksClient({
jwksUri: 'https://sandrino.auth0.com/.well-known/jwks.json',
proxy: 'https://username:pass@address:port'
});
// NEW
const HttpsProxyAgent = require('https-proxy-agent');
const newClient = jwksClient({
jwksUri: 'https://sandrino.auth0.com/.well-known/jwks.json',
requestAgent: new HttpsProxyAgent('https://username:pass@address:port')
});
The library no longer gates what http(s) Agent is used, so we have removed requestAgentOptions and now expose the requestAgent option when creating a jwksClient.
// OLD
const oldClient = jwksClient({
jwksUri: 'https://sandrino.auth0.com/.well-known/jwks.json',
requestAgentOptions: {
ca: fs.readFileSync(caFile)
}
});
// NEW
const newClient = jwksClient({
jwksUri: 'https://sandrino.auth0.com/.well-known/jwks.json',
requestAgent: new https.Agent({
ca: fs.readFileSync(caFile)
})
});
The library no longer supports callbacks. We have migrated to async/await(promises).
// OLD
client.getSigningKey(kid, (err, key) => {
const signingKey = key.getPublicKey();
});
// NEW
const key = await client.getSigningKey(kid);
const signingKey = key.getPublicKey();
With version 2 we have added full JWK/JWS support. With this we have bumped the node version to minimum 10. We have also removed Axios and exposed a fetcher option to allow user's to completely override how the request to the jwksUri endpoint is made.
Added
Changed
The proxy option has been removed from the JwksClient. Support for it was a little spotty through Axios, and we wanted to allow users to have more control over the flow. Now you can specify your proxy by overriding the requestAgent used with an agent with built-in proxy support, or by completely overriding the request library with the fetcher option.
// OLD
const oldClient = jwksClient({
jwksUri: 'https://sandrino.auth0.com/.well-known/jwks.json',
proxy: 'https://username:pass@address:port'
});
// NEW
const HttpsProxyAgent = require('https-proxy-agent');
const newClient = jwksClient({
jwksUri: 'https://sandrino.auth0.com/.well-known/jwks.json',
requestAgent: new HttpsProxyAgent('https://username:pass@address:port')
});
The library no longer gates what http(s) Agent is used, so we have removed requestAgentOptions and now expose the requestAgent option when creating a jwksClient.
// OLD
const oldClient = jwksClient({
jwksUri: 'https://sandrino.auth0.com/.well-known/jwks.json',
requestAgentOptions: {
ca: fs.readFileSync(caFile)
}
});
// NEW
const newClient = jwksClient({
jwksUri: 'https://sandrino.auth0.com/.well-known/jwks.json',
requestAgent: new https.Agent({
ca: fs.readFileSync(caFile)
})
});
The library no longer supports callbacks. We have migrated to async/await(promises).
// OLD
client.getSigningKey(kid, (err, key) => {
const signingKey = key.getPublicKey();
});
// NEW
const key = await client.getSigningKey(kid);
const signingKey = key.getPublicKey();
fix(release): exclude ts-output from 1.12.5 tarball
fix(release): exclude ts-output from 1.12.5 tarball (#501)
chore: bump axios to ^0.31.0 and release 1.12.4
chore: bump axios to ^0.31.0 and release 1.12.4
Add alg to SigningKey types \#220 (okko)
Added
Fixed
Added coverage folders to .npmignore
Fixed
Bump Axios to ^0.21.1 \#208 (72636c)
Deprecation We are deprecating passing in a jwksObject to the client for reasons laid out in \#292. In order to load keys from anything other than the…
Added
Deprecation
We are deprecating passing in a jwksObject to the client for reasons laid out in #292. In order to load keys from anything other than the jwksUri, please use the getKeysInterceptor.
const client = new JwksClient({
jwksUri: 'https://my-enterprise-id-provider/.well-known/jwks.json',
getKeysInterceptor: (cb) => {
const file = fs.readFileSync(jwksFile);
return cb(null, file.keys);
}
});
Added
Deprecation
We are deprecating passing in a jwksObject to the client for reasons laid out in #202. In order to load keys from anything other than the jwksUri, please use the getKeysInterceptor.
const client = new JwksClient({
jwksUri: 'https://my-enterprise-id-provider/.well-known/jwks.json',
getKeysInterceptor: (cb) => {
const file = fs.readFileSync(jwksFile);
return cb(null, file.keys);
}
});
Add ability to configure proxy with env vars \#188 (lubomir-haralampiev)
Added
fix proxy agent for http \#182 (NShahri)
getSigningKeys return algorithm \#168 (moander)
Added
Fixed
Update Buffer initialization to non-deprecated method \#154 (cwardcode)
Added
Fixed
Security
Fix #139 strictSsl: false option being ignored \#146 (kopancek)
Migrate from Deprecated Request Lib \#135 (davidpatrick)
This release includes a change to the default caching mechanism. Caching is on now by default, with the decrease of the default time of 10hours to 10m
This release includes a change to the default caching mechanism. Caching is on now by default, with the decrease of the default time of 10hours to 10minutes. This change introduces better support for signing key rotation.
Added
Changed
Fixed
This is in response to an unintended breaking change that was introduced as part of the last Typescript definitions change, included in the release wi…
This patch release includes an alias for accessing the public key of a given JSON Web Key (JWK). This is in response to an unintended breaking change that was introduced as part of the last Typescript definitions change, included in the release with version 1.6.0.
Now, no matter what the public key algorithm is, you can obtain it like this:
client.getSigningKey(kid, (err, jwk) => {
const publicKey = jwk.getPublicKey();
});
Fixed
NPM dependencies update \#112 (ecasilla)
Add agentOptions to customize request TLS/SSL options. https://github.com/auth0/node-jwks-rsa/pull/84
Added
agentOptions to customize request TLS/SSL options. https://github.com/auth0/node-jwks-rsa/pull/84Now includes the jsonwebtoken as a runtime dependency not dev to avoid breaks with 1.5.0 installs
Changed
Integrate with passport-jwt \#77 (gconnolly)
Allow custom headers in request #77 (Mutmatt)
[1.4.0] - (2019-02-07) Added
Adding support for hapi 17.x.x \#38 (degrammer)
### Changed - Fixed TypeScript definition
### Added - Koa integration ### Changed - ms updated to v2.0.0
ms updated to v2.0.0Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →