NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2971 most downloaded on npm
OAuth 2 / OpenID Connect Client API for JavaScript Runtimes
Last release 29 days ago
05 Sep 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
62 versions withdrawn
withdrawn after publishing
10 years old
223 releases · first in 2016
allow duplicate "kid" values in issuer's jwks_uri (sigh)
enabled full JWT validation on distributed and aggregated claims
One column per quarter.
skip validating iat is in the past
remove check for nonce presence in params
check for mTLS request options during token_endpoint calls
use shake256(m, 114) for Ed448 ID Token _hash claims
Nothing published for this version
assert jwks is present for private_key_jwk first
use sha512 for Ed25519 and shake256 for Ed448 ID Token _hash claims
allow tokenType for userinfo to use as authorization header scheme
allow distributed claims to be missing from the response (48d6633), closes #197
### Bug Fixes * use updated jose package
typescript: add missing Strategy interface properties (c0d59c4), closes #189
typescript: remove the need for @types/got dependency
assert client_secret is present when required, require client_id, etc
device authorization request always pushes the client_id to body
ignore runtime unsupported or malformed issuer jwks
add RFC8628 - OAuth 2.0 Device Authorization Grant (Device Flow) support
added Node.js lts/dubnium support for runtime supported features
### Features * electron v6.x runtime support
option to change http options globally
strategy: do not modify the params argument, clone it instead (4731d29), closes #177
give AAD v2 organizations and consumers same treatment as common (4891b5b), closes #175
plug reported lodash vulnerability
added support for direct symmetric key encryption alg (dir)
ensure runtime @panva/jose dependency ^1.3.0
passport strategy runtime authenticate parameters regression (36e741e), closes #167
add helpers for generating secure random values & PKCE challenges
Strict === equality operator is now used for assertions, while unlikely the breaking change is that should some ID Token claims be correct values but…
response_type=tokenclient_secret value rather then
its SHA digestapplication/jwtredirect_uri or response_type on a client instance. I sympathize and
openid-client will now take these common mistakes and accomodate.#client.authorizationParams() will now attempt to resolve the redirect_uri and
response_type from your client's metadata. If there's only one listed, it will be used
automatically. If there's more, you must continue providing it explicitly.resource to authorization code or refresh token exchange,
you can now pass those in the actual client methods.@panva/jose for all things JOSE. As a result of this the minimum required
node version is v12.0.0 and the client will now only function in node.js environments.Issuer.defaultHttpOptions getter and setter were removed. See documentation customization
section for its replacement.client.CLOCK_TOLERANCE client property was removed. See documentation customization section for
its replacement.client.authorizationCallback() has been renamed to client.callback()tokenset.claims getter is now a function tokenset.claims()useRequest and useGot methods were removed, with the maintenance mode and inevitable
deprecation of the request module i've decided to only support got as an http request library.keystore options argument properties are now called just jwks.response_type=code is no longer defaulted to in #client.authorizationUrl() if your client
instance has multiple response_types members.=== equality operator is now used for assertions, while unlikely the breaking change is
that should some ID Token claims be correct values but incorrect type, these will start failing now.#client.revoke() no longer returns or in any way processes the response body as per spec
requirements.key lookup cache is now working as intended (90d2f2a), closes #162
upgrade min node-jose version to fix its performance in node
strategy code_verifier length, removed uuid dependency (60d0cb8...ea4a8fd), closes #131
assign Discovery 1.0 defaults when discovering with .well-known
non-string error responses are not treated as OpenIdConnectError (782d464), closes #125
lts/boron unsupported syntax fix
apply safer, simpler www-authenticate parsing regex
authorization response parameter checking based on response_type
improved discovery support of custom .well-known suffixes
added support for RFC8414 - OAuth 2.0 Authorization Server Metadata discovery
encrypted_id_token property added to TokenSet instances with the value of the encrypted ID Token value before its decryptionfixed handling of bearer endpoint responses with www-authenticate headers only.
node-jose dependency bumped to major ^1.0.0 - fixes A\d{3}GCMKW symmetrical encryption support
node-jose dependency bumped to major ^1.0.0 - fixes A\d{3}GCMKW symmetrical encryption supportfixed circular when serializing OpenIdConnectError
base64url dependency replaced with base64-url
base64url dependency replaced with base64-urlNothing published for this version
NOTE: Although technically a fix, this is a breaking change when used with providers that also don't currently follow the standard. A proper way of su…
client_secret_basic requiring the username and password tokens to be x-www-form-urlencoded
according to https://tools.ietf.org/html/rfc6749#section-2.3.1
client_secret_basic is Authorization: base64(formEncode(client_id):formEncode(client_secret)). If your client_id and client_secret does contain special characters that need encoding this does not affect you. If it does, try using client_secret_post instead.removed deprecated client#grantAuth
client#grantAuthClient#registerOpenIDConnectStrategy as single argument, use new Strategy({ client }) instead of new Strategy(client).response_type=noneadded documentation for OpenIdConnectError
OpenIdConnectErrorerror_uri from IdP responses to OpenIdConnectError instancesOpenIdConnectError messages to include error_descriptionOpenIdConnectErrorerror_uri from IdP responses to OpenIdConnectError instancesOpenIdConnectError messages to include error_descriptionIssuer.discover now parses the provided URI instead of just inspecting the string. #80
Issuer.discover now parses the provided URI instead of just inspecting the string. #80fixed edge cases of (and simplified) private id token decryption method
fix return values of #authorizationCallback() for response_type=none to resolve a TokenSet
#authorizationCallback() for response_type=none to resolve a TokenSetfixed authorizationUrl to respect existing issuer authorization_endpoint query parameters
authorizationUrl to respect existing issuer authorization_endpoint query parametersadjusted the passport state mismatch related error message to hint developers at a local setup issue
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
now uses client_secret_post as default for Issuer instances that do not support client_secret_basic but do signal support for client_secret_post in th
client_secret_post as default for Issuer instances that do not support
client_secret_basic but do signal support for client_secret_post in their discovery documentadded s_hash value validation support for ID Tokens returned by authorization endpoint
s_hash value validation support for ID Tokens returned by authorization endpoint_hash but from invalid sha-length was acceptedadded support for Request Objects encrypted with symmetrical keys
added Passport Strategy passReqToCallback option, defaults to false
passReqToCallback option, defaults to falseYour coding agent can read these notes before it upgrades. Set up the MCP server →