NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1513 most downloaded on PyPI
A minimal JSON Web Token authentication plugin for Django REST Framework
Last release 1 years ago
21 Jul 2025
Release timing varies
gaps range from 3 weeks to 1.1 years
Some releases are documented
notes for 27 of 48 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
48 releases · first in 2017
Missing Migration for rest_framework_simplejwt.token_blacklist app. A previously missing migration (0013_blacklist) has now been added. This issue aro
Missing Migration for rest_framework_simplejwt.token_blacklist app. A previously missing migration (0013_blacklist) has now been added. This issue arose because the migration file was mistakenly not generated earlier. This migration was never part of an official release, but users following the latest master branch may have encountered it.
Notes for Users
If you previously ran makemigrations in production and have a 0013_blacklist migration in your django_migrations table, follow these steps before upgrading:
python manage.py migrate rest_framework_simplejwt.token_blacklist 0012python manage.py migrateImportant: If other migrations depend on 0013_blacklist, be cautious when removing it. You may need to adjust or regenerate dependent migrations to ensure database integrity.
for_user usage by @vgrozdanic in #872iat claim from refresh token by @vgrozdanic in #888Full Changelog: v5.5.0...v5.5.1
One column per quarter.
Missing Migration for rest_framework_simplejwt.token_blacklist app. A previously missing migration (0013_blacklist) has now been added. This issue arose because the migration file was mistakenly not generated earlier. This migration was never part of an official release, but users following the latest master branch may have encountered it.
Notes for Users If you previously ran makemigrations in production and have a 0013_blacklist migration in your django_migrations table, follow these steps before upgrading:
python manage.py migrate rest_framework_simplejwt.token_blacklist 0012
python manage.py migrate
Important: If other migrations depend on 0013_blacklist, be cautious when removing it. You may need to adjust or regenerate dependent migrations to ensure database integrity.
for_user usage by @vgrozdanic in https://github.com/jazzband/djangorestframework-simplejwt/pull/872iat claim from refresh token by @vgrozdanic in https://github.com/jazzband/djangorestframework-simplejwt/pull/888Adds new refresh tokens to OutstandingToken db. by @thecarpetjasp in #866
Full Changelog: v5.4.0...v5.5.0
Note, many deprecated versions are only officially not supported but probably still work fine.
Token.for_user to allow subclasses by @sterliakov in #776Null value of the OutstandingToken of the BlacklistMixin.blacklist by @JaeHyuckSa in #806Full Changelog: v5.3.1...v5.4.0
Token.for_user to allow subclasses by @sterliakov in https://github.com/jazzband/djangorestframework-simplejwt/pull/776Null value of the OutstandingToken of the BlacklistMixin.blacklist by @JaeHyuckSa in https://github.com/jazzband/djangorestframework-simplejwt/pull/806Full Changelog: https://github.com/jazzband/djangorestframework-simplejwt/compare/v5.3.1...v5.4.0
Remove usages of deprecated datetime.utcnow() and datetime.utcfromtimestamp() by @kozlek in #765
Full Changelog: v5.3.0...v5.3.1
[pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #641
django.po for id translation by @kiraware in #685Full Changelog: v5.2.2...v5.3.0
Fix typo in blacklist_app.rst by @cbscsm in #593
use non-deprecated UTC timezone by @BSVogler in #606
Full Changelog: v5.2.0...v5.2.1
Remove the JWTTokenUserAuthentication from the Experimental Features #546 by @byrpatrick in #547
Full Changelog: v5.1.0...v5.2.0
Fix default_app_config deprecation
Meta:
Translations:
Set BLACKLIST_AFTER_ROTATION by default to False by @mohmyo in #455
Full Changelog: v4.8.0...v5.0.0
Add integration instructions for drf-yasg
https://github.com/jazzband/djangorestframework-simplejwt/blob/master/CHANGELOG.md#version-472
https://github.com/jazzband/djangorestframework-simplejwt/blob/master/CHANGELOG.md#version-472
media_type (#426)default_app_config deprecation (#415)INSTALLED_APPS for SimpleJWT iff you want translations (#420)TokenRefreshSerializer (#396)INSTALLED_APPS (#416)Translations:
Fixed user-generated migration file bug in token_blacklist
Added support for Django 3.2 and drop Django 3.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Restricted setup.py config to Python 3 only.
setup.py config to Python 3 only.Included translation files in release package.
Updated python-jose version requirement.
python-jose version requirement.Fixed KeyError in TokenObtainSerializer.validate.
KeyError in TokenObtainSerializer.validate.Added request pass-through on django.contrib.auth.authenticate call in TokenObtainSerializer.
django.contrib.auth.authenticate call in
TokenObtainSerializer.TokenObtainSerializer to use fail API from parent class.Nothing published for this version
Nothing published for this version
Removed official support for Python 3.4.
Fixed issue with WWW-Authenticate header not being included in 401 responses.
WWW-Authenticate header not being included in 401
responses.Added missing method get on Token base class.
get on Token base class.Simplified some blacklist app code.
Added TokenObtainSerializer.get_token method to facilitate customization of token claims.
TokenObtainSerializer.get_token method to facilitate customization
of token claims.TokenVerifyView to allow verification of HMAC-signed tokens by API
users who have no access to the signing key.AUTH_HEADER_TYPE setting to AUTH_HEADER_TYPES. This setting
now contains either a single valid auth header type or a list or tuple of
valid auth header types. If authentication fails, and more than one string is
present in this tuple or list, the first item in the list will be used to
build the "WWW-Authenticate" header in the response.Moved handling of TokenError exceptions from inside of serializer validate methods into token view post methods.
validate
methods into token view post methods.Added support for refresh token rotation via ROTATE_REFRESH_TOKENS and BLACKLIST_AFTER_ROTATION settings. See README for details.
ROTATE_REFRESH_TOKENS and
BLACKLIST_AFTER_ROTATION settings. See README for details.BlacklistMixin.blacklist method to make it easier to blacklist tokens
regardless of whether or not they are present in the outstanding token list.OutstandingToken.jti field to char field to
better reflect JWT spec.AUTH_TOKEN_CLASS setting to AUTH_TOKEN_CLASSES. This setting now
specifies a list of token classes (or class paths) which are used to verify
tokens which are submitted for authorization. This will hopefully help
anyone wishing to gradually migrate between using different token types.SECRET_KEY setting to SIGNING_KEY.SIGNING_KEY setting now acts doubly as a symmetric
signing/verification key for HMAC algorithms and as a private key for RSA
algorithms.VERIFYING_KEY setting for use with RSA algorithms.TOKEN_BACKEND_CLASS setting.Switched to using PyJWT as the underlying library for signing and verifying tokens.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →