NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3164 most downloaded on npm
Low-Level OAuth 2 / OpenID Connect Client API for JavaScript Runtimes
Last release 29 days ago
05 Sep 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
7 versions withdrawn
withdrawn after publishing
4 years old
79 releases · first in 2022
One column per quarter.
accept space runs in Bearer and DPoP credentials
types: expose custom fetch duplex option
missing header.jwk in DPoP Proof JWT is now an OPE instead of TypeError
account for an upcoming Web Cryptography change
use duplex: half for resourceRequest with ReadableStream body input
relax www-authenticate auth-param presence requirement
remove mention of Edge Runtime from the readme
DPoP: add header JWK alg and pub when using ML-DSA keys
support ML-DSA JWS Algorithm Identifiers
optional recognition of proprietary or unrecognized token types
skip checking www-authenticate if expected status is received (596ae33), closes #191
### Fixes * allow 0 in auth_time
add request's url as a signal function option argument
RFC9728: keep any terminating "/" when pathname is present
RFC8414: strip any terminating "/" when pathname is present
expose internal symbol to skip use of PKCE for authorization code flow (d5748d0), closes #176
use GitHub Flavored Markdown for notes and warnings
correct note about bodyUsed in ResponseBodyError and WWWAuthenticateChallengeError
support for RFC-to-be 9728 - OAuth 2.0 Protected Resource Metadata
hardcode spec revision links (e.g. final or errata)
add support for Dynamic Client Registration
consistent DPoP Proof capitalization
add note about minimal Node.js version to README.md
add a helper to DPoPHandle to calculate dpop_jkt
add Client-Initiated Backchannel Authentication
assert success content-type only if JSON parsing fails
types: move customFetch options into its own interface
more descriptive "not a conform" message
shake the supported function when not needed
simpler consume of Request bodies
add support for form_post Request instance in hybrid response mode validate response functions
jweDecrypt is no longer an allowed symbol on the Client interface, it is instead an option passed to functions that may encounter encrypted assertions
DPoP() exported function. This returns a handle that also maintains its own LRU nonce cachesprocessAuthorizationCodeOpenIDResponse() method was removed in favour of processAuthorizationCodeResponse()processAuthorizationCodeOAuth2Response() method was removed in favour of processAuthorizationCodeResponse()processRefreshTokenResponse() or processDeviceCodeResponse()auth_time is now required in all ID Tokens if client.default_auth_time is setallowInsecureRequests in the HttpRequestOptions interface to revert this behaviour.isOAuth2Error() helper, all functions that used to possibly return an OAuth2Error now reject with ResponseBodyError or AuthorizationResponseError insteadparseWwwAuthenticateChallenges(), all functions verify process Response now reject with WWWAuthenticateChallengeError insteadprotectedResourceRequest() now rejects with WWWAuthenticateChallengeError when the Response has onedeprecate the useMtlsAlias symbol and options
add a hook for decrypting JWE assertions
support generic token endpoint grant requests
add non-repudiation signature validation methods
### Features * build: add jsr.io distribution
error msg when ID Token aud is an array and azp is missing
use correct "htm" in DPoP Proof via protectedResourceRequest (3ce3be2), closes #132
graduate jwksCache to stable API
allow ID Token auth_time to be present even if client.require_auth_time is false
add experimental support for edge compute runtimes JWKS caching
types: add explicit type to all exported functions
make protectedResourceRequest headers argument optional
normalize authorization_details and max_age in issueRequestObject
Nothing published for this version
types: add interfaces for RFC 9396 (Rich Authorization Requests)
graduate recently added experimental features to stable API
check that DPoP Proof iat is recent enough
add experimental support for validating JWT Access Tokens
allow fragment response as URL in validateDetachedSignatureResponse
add experimental support for FAPI 1.0
add experimental customize fetch option (e98c1aa), closes #94
DPoP: clockSkew in ProtectedResourceRequestOptions is a unique Symbol
handle Response objects with empty string url in processDpopNonce
Revert "fix: encode client_secret_basic - _ . ! ~ * ' ( ) characters"
Revert "fix: encode client_secret_basic - _ . ! ~ * ' ( ) characters"
This reverts commit f926175cdf6caa467029a57e76375054fff7c57b, even though it is the correct implementation some of the most widely used identity providers don't follow the specification.
add distribution links to README.md
create Request instances before passing them to fetch
add the cause property to errors where possible
Your coding agent can read these notes before it upgrades. Set up the MCP server →