PackageTrack
Sign in Get early access

aim_server_jwt

JWT authentication middleware for Aim framework. Provides stateless authentication with HS256 support, standard claims validation, and Bearer token verification.

0.1.1 aim-dart/aim

What this package is like to depend on

Last release 7 months ago

20 Jan 2026

Too new to tell

only 2 release windows

Nearly every release is documented

notes for 3 of 3 stable releases

Nothing withdrawn

no release was ever pulled

7 months old

3 releases · first in 2025

3 releases in the last 12 months

see the full history below

Release timeline

3 releases · Dec 2025 to Jan 2026
2026
Release Pre-release

Releases

latest 3
  1. 0.1.1 20 Jan 2026
    Release notes

    Internal fixes. No functional changes.

    Open source →
    Release notes

    Internal fixes. No functional changes.

    Open source →
    Release notes Open source →
  2. 0.1.0 20 Jan 2026
    Release notes

    Changelog

    0.1.0

    First beta release of Aim Framework - a modular ecosystem for Dart.

    Highlights

    • Lightweight, fast web server framework
    • Native PostgreSQL driver (no external dependencies)
    • Type-safe ORM with Record syntax
    • CLI tools with hot reload and database migrations

    Web Server (aim_server)

    • HTTP server built on Dart's native HttpServer
    • Path-based routing with parameter support (/users/:id)
    • Composable middleware chain
    • JSON, text, HTML response handling
    • Real-time SSE streaming support
    • Custom error handlers (404, global)

    Middleware Packages

    • aim_server_cors: CORS configuration
    • aim_server_cookie: Secure cookie management
    • aim_server_form: Form data parsing
    • aim_server_multipart: File upload handling
    • aim_server_static: Static file serving
    • aim_server_logger: HTTP request logging
    • aim_server_sse: Server-Sent Events
    • aim_server_jwt: JWT authentication
    • aim_server_basic_auth: Basic authentication

    Testing (aim_server_testing)

    • Test helpers and matchers
    • Mock objects for unit testing
    • Integration test utilities

    Database (aim_database + aim_postgres)

    • Database abstraction layer
    • Native PostgreSQL Wire Protocol implementation
    • SSL/TLS support (disable, allow, prefer, require, verify-ca, verify-full)
    • Authentication: cleartext, MD5, SCRAM-SHA-256
    • Named parameters (:name) and positional parameters ($1)
    • Transaction support with automatic commit/rollback

    ORM (aim_orm + aim_orm_postgres + aim_orm_codegen)

    • Type-safe table definitions using Dart Record syntax
    • Column types: integer, bigint, varchar, text, boolean, timestamp, uuid, json
    • Column modifiers: primaryKey, unique, nullable, withDefault, indexed
    • Query builders: SELECT, INSERT, UPDATE, DELETE
    • Condition operators: eq, gt, lt, gte, lte, inList
    • Code generation with build_runner

    CLI (aim_cli)

    • aim create <name>: Project scaffolding
    • aim dev: Development server with hot reload
    • aim build: Production build with native compilation
    • aim db:generate: Migration SQL generation from schema diff
    • aim db:migrate: Apply pending migrations
    • aim db:rollback: Rollback migrations
    • aim db:status: Show migration status

    Known Limitations

    • ORM Relations (1:1, 1:N, N:N) not yet supported
    • SQLite driver not yet available
    • db:reset command not yet implemented

    Requirements

    • Dart SDK: ^3.10.0
    • PostgreSQL: 9.5+ (SCRAM-SHA-256 requires 10+)
    Open source →
    Release notes

    First beta release of Aim Framework - a modular ecosystem for Dart.

    Highlights

    • Lightweight, fast web server framework
    • Native PostgreSQL driver (no external dependencies)
    • Type-safe ORM with Record syntax
    • CLI tools with hot reload and database migrations

    Web Server (aim_server)

    • HTTP server built on Dart's native HttpServer
    • Path-based routing with parameter support (/users/:id)
    • Composable middleware chain
    • JSON, text, HTML response handling
    • Real-time SSE streaming support
    • Custom error handlers (404, global)

    Middleware Packages

    • aim_server_cors: CORS configuration
    • aim_server_cookie: Secure cookie management
    • aim_server_form: Form data parsing
    • aim_server_multipart: File upload handling
    • aim_server_static: Static file serving
    • aim_server_logger: HTTP request logging
    • aim_server_sse: Server-Sent Events
    • aim_server_jwt: JWT authentication
    • aim_server_basic_auth: Basic authentication

    Testing (aim_server_testing)

    • Test helpers and matchers
    • Mock objects for unit testing
    • Integration test utilities

    Database (aim_database + aim_postgres)

    • Database abstraction layer
    • Native PostgreSQL Wire Protocol implementation
    • SSL/TLS support (disable, allow, prefer, require, verify-ca, verify-full)
    • Authentication: cleartext, MD5, SCRAM-SHA-256
    • Named parameters (:name) and positional parameters ($1)
    • Transaction support with automatic commit/rollback

    ORM (aim_orm + aim_orm_postgres + aim_orm_codegen)

    • Type-safe table definitions using Dart Record syntax
    • Column types: integer, bigint, varchar, text, boolean, timestamp, uuid, json
    • Column modifiers: primaryKey, unique, nullable, withDefault, indexed
    • Query builders: SELECT, INSERT, UPDATE, DELETE
    • Condition operators: eq, gt, lt, gte, lte, inList
    • Code generation with build_runner

    CLI (aim_cli)

    • aim create <name>: Project scaffolding
    • aim dev: Development server with hot reload
    • aim build: Production build with native compilation
    • aim db:generate: Migration SQL generation from schema diff
    • aim db:migrate: Apply pending migrations
    • aim db:rollback: Rollback migrations
    • aim db:status: Show migration status

    Known Limitations

    • ORM Relations (1:1, 1:N, N:N) not yet supported
    • SQLite driver not yet available
    • db:reset command not yet implemented

    Requirements

    • Dart SDK: ^3.10.0
    • PostgreSQL: 9.5+ (SCRAM-SHA-256 requires 10+)
    Open source →
    Release notes Open source →
  3. 0.0.1 30 Dec 2025
    Release notes

    Initial release - JWT authentication middleware for Aim framework

    Features

    • JWT authentication middleware: Automatic Bearer token validation
    • Token generation: Create JWT tokens with standard and custom claims
    • HMAC-SHA256 (HS256): Secure token signing with minimum 32-character secrets
    • Standard claims support: Full support for iss, sub, aud, exp, iat, nbf claims
    • Automatic validation: Signature verification, expiration, and claim validation
    • Path exclusion: Skip authentication for specific routes (e.g., /login, /public)
    • Type-safe design: Sealed class architecture with compile-time safety
    • Custom exception: JwtException for clear error handling
    • Context integration: JWT payload accessible via c.variables.jwtPayload

    Supported Algorithms

    • HS256 (HMAC-SHA256) - Symmetric key algorithm
    • 🔜 RS256 (RSA-SHA256) - Coming soon
    • 🔜 ES256 (ECDSA-SHA256) - Coming soon

    Examples

    import 'dart:io';
    import 'package:aim_server/aim_server.dart';
    import 'package:aim_server_jwt/aim_server_jwt.dart';
    
    void main() {
      final app = Aim<JwtEnv>(
        envFactory: () => JwtEnv.create(
          JwtOptions(
            algorithm: HS256(
              secretKey: SecretKey(secret: 'your-secret-key-at-least-32-chars'),
            ),
            excludedPaths: ['/login'],
          ),
        ),
      );
    
      // Apply JWT middleware
      app.use(jwt());
    
      // Login endpoint
      app.post('/login', (c) async {
        final jwt = Jwt(options: c.variables.jwtOptions);
        final token = jwt.sign({'user_id': 1, 'role': 'admin'});
        return c.json({'token': token});
      });
    
      // Protected endpoint
      app.get('/profile', (c) async {
        final payload = c.variables.jwtPayload;
        return c.json({
          'user_id': payload['user_id'],
          'role': payload['role'],
        });
      });
    
      app.serve(host: InternetAddress.anyIPv4, port: 8080);
    }
    

    Security

    • Enforces RFC 7518 minimum secret length (32 characters for HS256)
    • Automatic token expiration validation
    • Signature verification on every request
    • Bearer token format validation
    • Standard JWT claims validation (iss, aud, exp, nbf)
    Open source →

Every package, every release, already written down.

The archive is open and free. Watching your own project is what we are building next.

Browse the archive