NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #283 most downloaded on pub.dev
An easy to use JSON Web Token (JWT) implementation in Dart with all algorithms supported.
Last release 5 months ago
19 Apr 2026
Release timing varies
gaps range from 2 weeks to 7 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
6 years old
67 releases · first in 2020
One column per quarter.
Internal lint cleanups ( super.message , string interpolation, remove deprecated library directive)
aud list verification crashing on JSON-decoded tokens (List<dynamic> to List<String> cast)exp, nbf and iat claims (throw JWTInvalidException instead of runtime error)package:lints/recommended with strict-casts/inferencesuper.message, string interpolation, remove deprecated library directive)Replace ed25519_edwards with vendored Ed25519 implementation (enable dart2wasm compilation)
Use constant-time comparison for HMAC signature verification (timing-attack resistant)
JWT.decode (audience, issuer, subject, jwtId)aud claim as generic List in _parseAudECPrivateKey.bytes, derive EC private key size from parametersRollback to a dynamic JWT.payload
Increase JWT.payload strictness
JWT.payload strictness (https://github.com/jonasroussel/dart_jsonwebtoken/issues/67)Update upper bound of pointycastle
pointycastle for HMAC calculation instead of cryptocollection packageRollback collection to 1.17.1 to be compatible with older flutter versions
collection to 1.17.1 to be compatible with older flutter versionsFix unconsistant JWK convertion
JWTKey.fromJWK static method for parsing JWK to various key typesPossible BREAKING CHANGE : exp , nbf and iat are now following the JWT RFC for NumericDate by only using UTC DateTime
exp, nbf and iat are now following the JWT RFC for NumericDate by only using UTC DateTimetoJWK())exp, nbf and iatParse standard parameters when using JWT.decode
JWT.decode (https://github.com/jonasroussel/dart_jsonwebtoken/pull/64)Add support of PEM parsing for EdDSA keys with EdDSAPrivateKey.fromPem and EdDSAPublicKey.fromPem
EdDSAPrivateKey.fromPem and EdDSAPublicKey.fromPemAdded support for PSS alogrithm varations
Ensure sub, iss, jti are strings
sub, iss, jti are strings (https://github.com/jonasroussel/dart_jsonwebtoken/pull/62)- Fix iat claim verification
iat claim verification (https://github.com/jonasroussel/dart_jsonwebtoken/pull/57)Add support for base64 encoded secrets
exp, nbf and iat checks by casting the value to intFix invalid ECDSA signature for keys that are not a multiple of 8 (e.g. secp521r1)
- Add testable date times
Fixing issue with custom headers
Making all JWTAlgorithm classes public (mainly to be mocked in tests)
JWTAlgorithm classes public (mainly to be mocked in tests)Removing basic_utils package that was incompatible with flutter web
basic_utils package that was incompatible with flutter webhelpers.dart and key parsing functions into key_parser.dartexample/example.dartNew RSA algorithm with PSS padding (PS256, PS384, PS512)
Adding a new class factory ECPublicKey.cert
ECPublicKey.certAdding basic_utils package to handle PEM & key parsing
basic_utils package to handle PEM & key parsingKeys (e.g. RSAPublicKey.cert and .bytes)Downgraing collection to 1.7.1 to be compatible with flutter_test
collection to 1.7.1 to be compatible with flutter_test- Updating dependencies - Fixing CHANGELOG.md
CHANGELOG.mdBREAKING CHANGE: Replacing all JWTError by JWTException that is more accurate
Migrating from pedantic to lints
pedantic to lintsparsing.dart has been replaced by more accurate CryptoUtils functions https://github.com/Ephenodrom/Dart-Basic-Utils
parsing.dart has been replaced by more accurate CryptoUtils functions https://github.com/Ephenodrom/Dart-Basic-Utils_ECDSAAlgorithm.sign method that did not filling the gap in the ECDSA curve signaturesFixing ECPrivateKey.raw initialize size
ECPrivateKey.raw initialize sizeAdding a .raw and .clone constructor to JWTKey (execpt SecretKey of course)
.raw and .clone constructor to JWTKey (execpt SecretKey of course)Fix rethrow of JWTError exceptions for the method verify. Before this change every exception thrown by verify always returned JWTUndefinedError
verify. Before this change every exception thrown by verify always returned JWTUndefinedErrorAdding a try version of decode, verify and sign, that simply returns null instead of throwing errors
try version of decode, verify and sign, that simply returns null instead of throwing errorsAdding a JWT.decode method to simply decode a token without checking its signature
JWT.decode method to simply decode a token without checking its signatureJWT.verify method do not remove extra token infos (iss, aud, ...) anymoreFix Flutter compatibility issue: downgrade dependency collection to 1.16.0
downgrade dependency collection to 1.16.0https://github.com/jonasroussel/dart_jsonwebtoken/commit/12348776259ccec70ccf62856ec0245f49ebe951
Formating for 'static analysis'
Fix : https://github.com/jonasroussel/dart_jsonwebtoken/issues/19
BREAKING CHANGE: JWT.audience is now an instance of the Audience class, to handle multiple audience entries and can be used like list. You can always…
JWT.audience is now an instance of the Audience class, to handle multiple audience entries and can be used like list. You can always use a single entry by calling Audience.one('...') factory and the .first getterpointycastle dependency to 3.3.4Some badges on README.md (Thanks to https://github.com/bruno-garcia/badges.bar)
README.md (Thanks to https://github.com/bruno-garcia/badges.bar)Fix the pointycastle dependency, v3.1.3 is incompatible with flutter web (dart2js)
pointycastle dependency, v3.1.3 is incompatible with flutter web (dart2js)
(https://github.com/jonasroussel/dart_jsonwebtoken/issues/14)Adding header in JWT class (you can now set your custom header)
header in JWT class (you can now set your custom header)Fixing EdDSA incompatibility's with flutter web
ed25519_edwards have been removed, convert & collection have been addedFixing _pkcs8ECPublicKey to work with pointycastle 3.0.1
_pkcs8ECPublicKey to work with pointycastle 3.0.1BREAKING CHANGE: jwt.verify no longer support throwUndefinedErrors parameter
JWTUndefinedError is thrown containing the original error in error property (https://github.com/jonasroussel/dart_jsonwebtoken/issues/9)jwt.verify no longer support throwUndefinedErrors parameterFixing JWT.sign to include iat & other attributes when payload is an empty Map
JWT.sign to include iat & other attributes when payload is an empty Map- Stable release for null safety
EdDSAPrivateKey and EdDSAPublicKey, two new keys for EdDSA algorithm
ed25519_edwards package has been addedNull safety migration of this package
Adding analysis_options.yaml to work with pedantic during development
analysis_options.yaml to work with pedantic during developmentFormating for 'static analysis'
New ECDSA Algorithm (ES256, ES384, ES512)
rsa_pkcs & cryptography have been removedNothing published for this version
Debuging _TypeError issue on sign method
_TypeError issue on sign method (#4)toString in the JWTError classFormating for 'static analysis'
Implementing throwUndefinedErrors option in the JWT.verify method
throwUndefinedErrors option in the JWT.verify methodFormating for 'static analysis'
Adding checks in JWT.verify function for iss, sub, aud, iat, jti
JWT.verify function for iss, sub, aud, iat, jtiFormating for 'static analysis'
Payload is now dynamic and not restricted to an object
- New algorithms
Your coding agent can read these notes before it upgrades. Set up the MCP server →