NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #875 most downloaded on npm
Implementation of JSON Web Signatures
Last release 10 months ago
04 Dec 2025
Ships unpredictably
gaps range from 3 weeks to 6.0 years
Most releases are documented
notes for 9 of 13 stable releases
12 versions withdrawn
withdrawn after publishing
14 years old
25 releases · first in 2013
Fix advisory GHSA-869p-cjfg-cm3x : createSign and createVerify now require that a non empty secret is provided (via opts.secret, opts.privateKey or op
* [MAJOR]: jwa was updated and now matches algorithm names case-sensitively. Should a jws header have an alg such as "es256" instead of the IANA regis
v4.0.0
* [MAJOR]: jwa was updated and now matches algorithm names
case-sensitively. Should a jws header have an alg such as "es256"
instead of the IANA registered "ES256" it will now throw.
See https://github.com/brianloveswords/node-jwa/releases/tag/v2.0.0
for more details
One column per quarter.
Fix advisory GHSA-869p-cjfg-cm3x : createSign and createVerify now require that a non empty secret is provided (via opts.secret, opts.privateKey or op
* jwa explicitly bumped to ^1.4.1 * KeyObject support * PS* interoperability fixes
v3.2.2
* jwa explicitly bumped to ^1.4.1
* KeyObject support
* PS* interoperability fixes
* Updated jws.ALGORITHMS with PS* algs
v3.2.1
* Updated jws.ALGORITHMS with PS* algs
* [MINOR] Support for PS256,PS384,PS512 through jwa update. Thanks @csprl ! * README updates. Thanks @Calinou !
* The base64url package has issues with TypeScript and also has an open vulnerability reported on HackerOne (not affected).
v3.1.5: inline base64url
* The base64url package has issues with TypeScript and also
has an open vulnerability reported on HackerOne (not
affected).
Most replacement packages are only compatible with Node 4+
so inlining an implementation in order to release with a
patch version
* Update README (Thanks @mmdf!)
package: version v3.1.4
package: version v3.1.4
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
See https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/ for details.
jwt.verify now requires an algorithm parameter, and
jws.createVerify requires an algorithm option. The "alg" field
signature headers is ignored. This mitigates a critical security flaw
in the library which would allow an attacker to generate signatures with
arbitrary contents that would be accepted by jwt.verify. See
https://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/
for details.BREAKING: Default payload encoding changed from binary to utf8. utf8 is a is a more sensible default than binary because many payloads, as far as I ca
BREAKING: Default payload encoding changed from binary to
utf8. utf8 is a is a more sensible default than binary because
many payloads, as far as I can tell, will contain user-facing
strings that could be in any language. (<code>6b6de48</code>)
Code reorganization, thanks @fearphage! (<code>7880050</code>)
encoding. For those few users
that might be depending on a binary encoding of the messages, this
is for them. (<code>6b6de48</code>)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →