NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2971 most downloaded on npm
OAuth 2 / OpenID Connect Client API for JavaScript Runtimes
Last release 29 days ago
05 Sep 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
62 versions withdrawn
withdrawn after publishing
10 years old
223 releases · first in 2016
added an optional keystore argument to Client#fromUri(uri, token, [keystore]) to pass a keystore with private asymmetrical keys
Client#fromUri(uri, token, [keystore]) to pass a keystore
with private asymmetrical keysClient#new calls to check that only private asymmetrical
keys are addedNothing published for this version
One column per quarter.
explicitly specified accepted response type via accept: application/json header
Nothing published for this version
relaxed #callbackParams to allow IncomingMessage lookalikes
['web'] to 'web'Issuer.httpClient setter to help advanced developers in complex environments
to change the used http request clientadded pure OAuth 2.0 stripped down callback function #oauthCallback
#oauthCallback#userinfo requests to have extra params in either query or bodyadded introspection/revocation specific client and issuer properties. To remain backwards compatible they default to their token endpoint counterparts
Nothing published for this version
Nothing published for this version
bumped node-jose dependency to avoid github tar.gz dependencies
#metadata getter.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
bumped minimum node-jose version to cover http://blog.intothesymmetry.com/2017/03/critical-vulnerability-in-json-web.html
Nothing published for this version
Nothing published for this version
Nothing published for this version
fixed an ID Token validation for ID Token returned by Token Endpoint that includes c_hash
_jwt auth methods when used in introspection and revocationdeprecated passing keystore directly to Client#register, pass an object with keystore property instead
Nothing published for this version
added error messages when expected response is missing
added #claims getter to TokenSets returned from authorizationCallback and refresh;
#claims getter to TokenSets returned from authorizationCallback and refresh;fixed unpacking aggregated claims with alg=none and no iss claim
Nothing published for this version
Nothing published for this version
fixed signed userinfo response validation in case iss, aud and similar ID Token claims are missing
RP test tools are passing, no changes required from the library, API is declared stable, hence 1.0.0 release.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →