NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #645 most downloaded on pub.dev
This plugin provides an abstraction around the Android and iOS AppAuth SDKs so it can be used to communicate with OAuth 2.0 and OpenID Connect providers
Last release 25 days ago
13 Sep 2026
Ships fairly regularly
a new release about every 2 months
Most releases are documented
notes for 48 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
8 years old
106 releases · first in 2019
Breaking change updated minimum supported SDK version to Flutter 3.44.0/Dart 3.12.0
[iOS] added custom browser support. Thanks to the PR from Kuurse
One column per quarter.
[iOS][macOS] improved SPM (Swift Package Manager) compatibility
Removed assertion around tied to idTokenHint and postLogoutRedirectUrl parameters passed to the EndSessionRequest constructor. This was done as both a
idTokenHint and postLogoutRedirectUrl parameters passed to the EndSessionRequest constructor. This was done as both are optional according to the OIDC RP-initiated logout specificationBreaking change updated minimum supported SDK version to Flutter 3.38.1/Dart 3.10. Consequently the minimum OS requirements for each platform has been…
Breaking change updated minimum supported SDK version to Flutter 3.38.1/Dart 3.10. Consequently the minimum OS requirements for each platform has been…
Potentiallu breaking change [Android] plugin will now throw a PlatformException with a null_activity error code when plugin runs into a scenario where…
Prompt class that exposes standard prompt string values as defined in the OIDC specification. Thanks to the PR from Valentin MichalakPlatformException with a null_activity error code when plugin runs into a scenario where the bound Flutter activity has been detached/disposed. Thanks to the PR from Sam CostaBreaking change updated minimum supported SDK version to Flutter 3.29/Dart 3.7
flutter_lints dev dependencycompileSdkVersion to 35 and AGP to 8.6.0[iOS][macOS] bumped AppAuth iOS dependency to 2.0.0
Breaking change updated minimum supported SDK version to Flutter 3.19/Dart 3.3
compileSdkVersion to 33 and AGP to 8.0.1 to align with what's used by the AppAuth Android SDKflutter_lints dev dependencyNothing published for this version
Nothing published for this version
[iOS][macOS] bumped AppAuth iOS dependency to 1.7.6
Fixed issue 568 where compilation could fail with a 'OIDExternalUserAgent.h' file not found error
'OIDExternalUserAgent.h' file not found errorBreaking change Replaced the preferEphemeralSession property in the AuthorizationRequest, AuthorizationTokenRequest and EndSessionRequest classes with…
preferEphemeralSession property in the AuthorizationRequest, AuthorizationTokenRequest and EndSessionRequest classes with externalUserAgent. Thanks to the PR from john-slow. externalUserAgent is presented by the newly ExternalUserAgent enum that has the following values
asWebAuthenticationSession: uses the ASWebAuthenticationSession APIs where possible. This is the default value and was the default behaviour behaviour that aligns with what the AppAuth iOS SDK would do in choosing the best available user-agentephemeralAsWebAuthenticationSession: uses an ephemeral session via the ASWebAuthenticationSession APIs. Applications that previously used preferEphemeralSession and specified to be true can migrate by specifying this enum valuesfSafariViewController: uses the SFSafariViewController APIsallowInsecureConnections has been done in response to issue 554AuthorizationService have been disposedFlutterAppAuthUserCancelledException when an authorization request has been cancelled as a result of the user closing the browser. For other scenarios the plugin will throw FlutterAppAuthPlatformException. See the API docs for both classes for more details on the available details. Both exception classes inherit from PlatformException so the changes should be backwards compatibleTheme.AppCompat.Translucent.NoTitleBar as the theme for the RedirectUriReceiverActivity from the AppAuth Android SDK. This is to fix a crash raised with issues #362 and #515authorize() or authorizeAndExchange(), rather than crashing the plugin will now throw a PlatformException with an error code of no_browser_available. Thanks to the PR from NikHomannPlatformException. Thanks to the PR from Johninit and to use initWithPresentingWindow via the AppAuth iOS/macOS SDK instead. Thanks to the PR from Ivan TivonenkoUpdated 8.0.0 as it was missing mention of the privacy manifest file to the macOS implementation of the plugin
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Breaking change Bumped minimum Flutter SDK version to 3.0.0 and Dart SDK version to 2.17
compileSdkVersion to 31 (Android 12)flutter_appauth plugin has done this change ahead of timeflutter run command on the stable channel (i.e. Flutter version 3.7.1) to debug/run the app will in an error that says "package identifier or launch activity not found". However, an APK or app bundle can still be built and will run on a device. The Flutter team have already addressed this issue on the master channel that is currently on version 3.10.0-17.0.pre.21 so would expect the next stable release to contain the fix. Alternatively developers can manually restore the package identifier though this change was done to avoid issues from happening in the futureAdded comments to example app to explain how code challenge takes place per PKCE. Thanks to PR from Davide Ravasi
[iOS][macOS] bumped AppAuth dependency to 1.6.0
Added preferEphemeralSession to EndSessionRequest Thanks to the PR from Daniel Ziegler
preferEphemeralSession to EndSessionRequest Thanks to the PR from Daniel ZieglerAdded missing credit to 4.1.0 changelog entry
queries in AndroidManifest.xml as that is now handled directly with the AppAuth Android SDKAdded ability to specify the nonce as part of requests. Thanks to the PR from Tiernan
nonce as part of requests. Thanks to the PR from TiernanBumped AppAuth iOS dependency. Thanks to PR from Didier Prophete
Added support for macOS. Thanks to the PR from Jordy Langen
[iOS] fix nonce not being returned correctly on iOS
nonce not being returned correctly on iOSBreaking change AuthorizationResponse's constructor now includes nonce and has changed to take positional parameters
AuthorizationResponse's constructor now includes nonce and has changed to take positional parametersnonce can now be specified for TokenRequest class. This is especially useful on Android as the AppAuth Android SKD had turned on ID token validation that results in nonce mismatch errors. These errors should no longer appear when using the nonce value returned by the AuthorizationResponse object after calling authorize() and passing the value to the TokenRequest when calling the token() methodAdded const constructor to FlutterAppAuth
FlutterAppAuthExample app has been updated to point to the new demo IdentityServer instance
[iOS] fixed issue with scopes not being sent correctly as they should've been space-delimited instead of comma-delimited. Thanks to the PR from Angle
scopes not being sent correctly as they should've been space-delimited instead of comma-delimited. Thanks to the PR from Angle WangAdded scopes property to TokenResponse class and AuthorizationTokenResponse class that inherits from it. Thanks to PR from leoshusar
scopes property to TokenResponse class and AuthorizationTokenResponse class that inherits from it. Thanks to PR from leoshusar[Android] claims can now be passed as part of the additionalParameters included with requests without triggering an exception by the AppAuth Android S
claims can now be passed as part of the additionalParameters included with requests without triggering an exception by the AppAuth Android SDK. Thanks to the PR from Garry Jeromson[Android] updated error handling so more details are returned. Thanks to Andreas Kägi for originally starting on the PR
Fix grammar in 2.1.0 changelog entry
[Android] ui_locales can now be passed as part of the additionalParameters included with requests without triggering an exception by the AppAuth Andro
ui_locales can now be passed as part of the additionalParameters included with requests without triggering an exception by the AppAuth Android SDK. Thanks to the PR from dimitristozBreaking change AuthorizationServiceConfiguration constructor has changed to take named parameters
AuthorizationServiceConfiguration constructor has changed to take named parametersendSession() method, EndSessionRequest and EndSessionResponse classes to support end session requestsallowInsecureConnections is true. Thanks to the PR from Roman FürstNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →