NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2971 most downloaded on npm
OAuth 2 / OpenID Connect Client API for JavaScript Runtimes
Last release 29 days ago
05 Sep 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
62 versions withdrawn
withdrawn after publishing
10 years old
223 releases · first in 2016
apply the default HTTP request timeout
One column per quarter.
allow destructuring the claims helper ( 38bd8c0 ), references #887
avoid undefined user-agent in fetchProtectedResource ( 492c3c3 ), references #885
types: expose custom fetch duplex option
apply optional non-repudiation on generic grant ID Tokens
note a workaround for redirect_uri with query string or bare origin ( e9689de ), closes #868
use duplex: half for fetchProtectedResource with ReadableStream body input
workaround dpop nonce caching caveats with customFetch
respect retry-after in CIBA and Device Authorization Grant polling
passport: include req.host from express@5 for ease of use in express@4
support for the ML-DSA Algorithm Identifiers
recognize N_A in the token exchange grant
fix TokenEndpointResponseHelpers.claims() note
RFC8414: strip any terminating "/" when pathname is present
revert to use 302 instead of 303 for the redirect
passport: automatically use form_post response mode when using hybrid response types
passport: handle JARM responses with authorizationCodeGrant instead of authorizationRequest
passport: allow custom query params in the initial authenticate() invocation
update implicitAuthentication and useIdTokenResponseType
support response_type=id_token OIDC Authentication Responses
hardcode spec revision links (e.g. final or errata)
allow client secret based auth factories to be used with DCR
add support for Dynamic Client Registration
use subpath export for JWE decryption dependency
improve docs for default client authentication (3c9f0d9), closes #761
improve docs for default client authentication (3c9f0d9), closes #761
passport: allow dpop handle to be retrieved with an async function
add a helper to DPoPHandle to calculate dpop_jkt
add Client-Initiated Backchannel Authentication
types: move customFetch options into its own interface
handle scope, prompt, and passReqToCallback from generic passport types (cc92a36), closes #735
passport: fix currentUrl when using express.Router (3b2d570), closes #733
resolve discovery customFetch jsdoc mentioning timeout
remove note from issuer transformation algorithm
rename the parameters positional argument in authorizationCodeGrant() (c79ccc5), closes #712
update link to passport example
add a server metadata helper for checking PKCE support
less options (removing support for processing deprecated response types, cutting down on the number of combinations that need to handled)
To that end openid-client@6 no longer supports the full cartesian matrix of response types and response modes, it no longer supports issuing encrypted assertions, decrypting assertions is limited to only a few algorithms, it no longer supports Dynamic Client Registration or Management, and Self-Issued OpenID Provider responses are also not supported.
The new API makes basic setups simple while allowing some degree of complexity where needed.
openid-client@6 is an ESM module using ES2022 syntax and it depends on WebCryptoAPI and Fetch API globals being available in the JS runtime.
openid-client@6 is written in TypeScript and its exported types come with comment annotations.
(Node.js) Versions 20.x and newer have all the necessary globals.
(Node.js) CJS style let client = require('openid-client') is possible in versions where process.features.require_module is true. This is a new Node.js feature slated to be released without a CLI flag in 23.x and 22.x
Nothing published for this version
Nothing published for this version
Nothing published for this version
jwt client authentication audience is now an issuer identifier string
Note: If needed this can be reverted using the extras.clientAssertionPayload option.
include DPoP Proof "htm" in requestResource if GET is defaulted to
avoid use of prototype attributes in keystore queries
Revert "fix: encode client_secret_basic - _ . ! ~ * ' ( ) characters"
Revert "fix: encode client_secret_basic - _ . ! ~ * ' ( ) characters"
This reverts commit 5a2ea80ef5e59ec0c03dbd97d82f551e24a9d348, even though it is the correct implementation some of the most widely used identity providers don't follow the specification.
encode client_secret_basic - _ . ! ~ * ' ( ) characters
add explicit Accept-Encoding header to http requests (abcb564), closes #648
consistent space encoding in authorizationUrl (#627) (ad68223), closes #626
experimental Bun support (a9d3a87), closes #622 #623
DPoP: remove experimental warning, DPoP is now RFC9449
handle empty client_secret with basic and post client auth (#610) (402c711), closes #609
### Fixes * bump oidc-token-hash
This release contains only code refactoring, dependency, or documentation updates. The release process now also uses provenance statements.
This release contains only code refactoring, dependency, or documentation updates. The release process now also uses provenance statements.
allow third party initiated login requests to trigger strategy (568709a), closes #510 #564
remove use of Node.js v8 builtin (f1881bc), closes #442 #475 #555
passport: ignore static state and nonce passed to Strategy()
typescript: requestResource returns a Promise (#546) (8bc9519), closes #488
### Features * JARM is now a stable feature
typescript: add client_id and logout_hint to EndSessionParameters
Your coding agent can read these notes before it upgrades. Set up the MCP server →