NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #1862 most downloaded on pub.dev
Flutter library for interacting with OAuth2 servers, with classes for transparent authorized requests, secure token storage, automatic token refreshing.
Last release 1 months ago
12 Aug 2026
Release timing varies
gaps range from 8 days to 10 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
68 releases · first in 2020
Securely generate larger parameters
Allow flutter_secure_storage versions 11.x
flutter_secure_storage versions 11.xOne column per quarter.
Update flutter_web_auth_2 to 6.x alpha
flutter_web_auth_2 to 6.x alphaflutter_web_auth_2Allow flutter_secure_storage versions 11.x
flutter_secure_storage versions 11.xAdd even more exception and stack trace infos
Improve even more error messages
Allow specifying a default http client in OAuth2Helper
OAuth2HelperCatch invalid_request errors in refreshToken (see also #13 )
invalid_request errors in refreshToken (see also #13)[4.2.4] - 2026/04/01 Improve exceptions/errors
Bump flutter_web_auth_2 to stable 5.x
flutter_web_auth_2 to stable 5.xBump flutter_secure_storage to stable 10.x
flutter_secure_storage to stable 10.xRemove unnecessary dependency on meta package
meta packageAdd support for optional parameters in revoke function
Fix issues with HTTP Content-Type headers using a dirty workaround
Content-Type headers using a dirty workaroundAllow changing the client ID and client secret key names
Updated all dependencies (with breaking changes!)
>=3.5.0 (it is the most common nowadays and basically required)web and add WASM supportsend HTTP requestsFix: Check for null value before casting scope to String (thanks xolf)
Updated dependencies (thanks Jason Held)
* Updated dependencies
Added Microsoft client (thanks Eradparvar).
* Updated dependencies * Small fixes
Migrated to `flutter_web_auth_2` (thanks ThexXTURBOXx & Piotr Mitkowski).
flutter_web_auth_2 (thanks ThexXTURBOXx & Piotr Mitkowski).flutter_lints (thanks ThexXTURBOXx).flutter_secure_storageOAuth2Client.accessTokenRequestHeaders class field. Use the proper getTokenWithAuthCodeFlow/getTokenWithClientCredentialsFlow parameters instead (see upgrading notes in the README).Fix for breaking change in flutter_secure_storage (thanks asmith26)
Fix accessing secure token storage on newer Android versions (thanks Piotr Mitkowski).
Fix for token renewal process through the refresh token flow
Expose the BaseStorage object (thanks Jon Salmon)
Fix: support fetching a new token when expired without a refresh token (thanks Tiernan)
* Small fix
Add Spotify client (thanks mauriciocartagena)
Fix: null check operator in WebAuth class (thanks jakub-bacic)
Allow passing optional parameters to web_auth "authenticate" method
Fix for authorization url params encoding
Support ephemeral sessions (thanks ThexXTURBOXx)
* Fixes (scope handling)
Fixes (incorrect scope handling with implicit grant, send empty client secret if specified)
* Web platform support!
AccessTokenResponse refactorization. It is now possible to retrieve custom response fields through the `getRespField` method
getRespField methodscopeSeparator paramComplete migration to sound null safety
Deprecated OAuth2Helper.setAuthorizationParams method
Add compatibility with http 0.13 (thanks bangfalse)
Fixes (make httpClient optional again in OAuth2Helper)
Added PUT, PATCH and HEAD methods to the OAuth2Helper class
Allows iOS token reading from storage when invoked in background task
Changed helper's token retrieval method
Added "delete" request method to helper class
Made "state" parameter optional
* Add implicit grant flow
Allow disabling PKCE when using OAuth2Helper
Bugfixes (check "expires_in" parameter type)
Bugfixes (add null-aware operators)
Token storage fix when scopes are empty
* Revocation token fixes
* Small fixes
scopes parameter become ooptional (as per the OAuth2 specs)
* Minor bugfixes.
Handled situations in which no new refresh token is returned upon a refresh flow.
Added revocation token ("logout") process
Bugfixes (optional scopes handling in the Access Token Response)
Bugfixes (multiple scopes handling)
Added trim for "scope" parameter
Your coding agent can read these notes before it upgrades. Set up the MCP server →