NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2971 most downloaded on npm
OAuth 2 / OpenID Connect Client API for JavaScript Runtimes
Last release 13 days ago
05 Sep 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
62 versions withdrawn
withdrawn after publishing
10 years old
223 releases · first in 2016
add client_id to endSessionUrl query strings
engines: remove package.json engines restriction
One column per quarter.
safeguard TokenSet prototype methods (7468674), closes #511
ignore non-conform "unrecognized" id_token in oauthCallback() (3425110), closes #503
improve support of electron BrowserWindow with nodeIntegration
typescript: add types export for nodenext module resolution
interoperable audience array value for JWT Client auth assertions (again)
### Fixes * dpop: htu without querystring
add application/jwk-set+json to accept header for JWKS calls (#467) (f94d42b), closes #466
passing null as checks.nonce should not disable it
allow setting timeout to 0 to disable it (32b28b5), closes #443
support OAuth 2.0 Authorization Server Issuer Identification
explicitly set content-length again (956c34b), closes #420
explicitly set accept: application/json again
The 'query' way of passing access token to userinfo was removed.
id_token code and grant_types accordinglyunpackAggregatedClaims and fetchDistributedClaims were removed with no replacement.response property attached to some RPError or OPError instances is now an instance of http.IncomingMessage. Its body is available on its body property as either JSON if it could be parsed, or a Buffer if it failed to pass as JSON./.well-known/oauth-authorization-server. To load such discovery documents pass full well-known URL to Issuer.discover.do not implicitly calculate key ids for Client instances (46e44e7), closes #379
update DPoP support to draft-03 (#407) (5565ee1), closes #406
OAuth 2.0 Pushed Authorization Requests (PAR) is now a stable feature
typescript: add remaining properties from RFC7662
typescript: add a missing PATCH method to requestResource (6b2c3ce), closes #368
fapi: validate ID Token's iat regardless of which channel it came from
typescript: add types for 4.6.0 additions
typescript: add types for 4.7.0 additions
add abort control over Device Flow Handle polling (#357) (f6faa68), closes #355 #356
added OAuth 2.0 Pushed Authorization Requests client API (e7af9f5), closes #259
interoperable audience array value for JWT Client auth assertions
use mtls token endpoint alias as audience when using jwt auth with mtls constrained tokens
include nbf in FAPIClient Request Objects
nbf in FAPIClient Request Objects (0be56ba)resolve discovery URIs one by one to yield consistent results (6b18218), closes #260 #267
hide AggregateError message stack (3011cca), closes #336
allow options.https.pfx for mTSL (075cad7), closes #326
typescript: add userinfo response generics
use base64url encoding in node when available
push pkce <> response type resolution to the authenticate function (1970af4), closes #312
typescript: add state property to AuthorizationParameters (#305) (b9dfa60), closes #304
add callback extras to strategy options
typescript: ts module interop issues with default export (6ca57d0), closes #291
OAuth 2.0 DPoP in various relevant API interfaces
updated request object mime-type as per draft-ietf-oauth-jwsreq-30
ensure minimal got version handles upcoming node version changes
the deprecated issuer.key() method was removed
issuer.key() method was removed^10.19.0 || >=12.0.0 < 13 || >=13.7.0 (also taking into account the got dependency update)v9.x to v11.x. If you override some of the http request options you will most certainly have to accomodate them.JWT to oauth.authz.req+jwtJWT to oauth.authz.req+jwtclient.userinfo() verb parameter was renamed to methodclient.resource() method was removed### Bug Fixes * typescript: add missing types
typescript: max_age in AuthorizationParameters is a number (5ce2a73), closes #279
allow AAD appid including discovery URLs to be multi-tenant
### Chores * dependency updates
fixup for removed lodash dependency (13a05fd), closes #272
### Bug Fixes * regression from #272
removes lodash dependency (7bc9b91), closes #272
give AAD v1 common same treatment as v2 common (2344e00), closes #269
allow any JSON numeric value for timestamp values (a24a759), closes #263
A192CBC-HS384 and A256CBC-HS512 direct encryption key derivation
add RPError indicators for unix timestamp comparison failures (fe3db5c), closes #250
typescript: add options arg to TypeOfGenericClient
assert refresh_token grant ID Token sub to equal previous
support additional authorized parties (c9268ce), closes #231
add support for RSA-OAEP-384 and RSA-OAEP-512 JWE algorithms
ensure jose version that handles ECDH-ES for larger key sizes right
allow multiple keys to match when selecting encryption key for request object
allow omitting the *_enc attributes (default 'A128CBC-HS256')
typescript: allow 'id_token token' as a response type
Your coding agent can read these notes before it upgrades. Set up the MCP server →