NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #266 most downloaded on PyPI
The ultimate Python library for JOSE RFCs, including JWS, JWE, JWK, JWA, JWT
Last release 1 months ago
29 Aug 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 47 of 47 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
47 releases · first in 2023
One column per quarter.
Add max_recipients on JWERegistry - by @lepture (d6dc8)
Released on August 29, 2026
JWK: Ignore keys with unknown kty values when importing a key set.
JWE: Add max_recipients to JWERegistry.
Prevent verify_general_json bypass empty signatures - by @lepture (f409f)
Released on July 13, 2026
Reject JWS general JSON serialization when signatures is empty.
Raises DecodeError when encrypted_key is None in JWE.
jws : Validate payload size for rfc7797 - by @lepture (683ca)
Released on July 8, 2026
Add default claims validation for iss, sub and aud.
Add size validation even for self-provided payload.
Avoid trailing padding for JWTs - by @lepture (dc415)
jwe : When decrypt, use the original aad base64 value - by @lepture (d6a3d)
Released on June 8, 2026
JWE: use the original aad value for decrypting.
jwk : As_dict, as_pem, as_der export public key by default - by @lepture (382b3)
Released on June 2, 2026
Drop Python 3.9 support.
Update type hints.
JWK: export public key by default in .as_dict, .as_pem, .as_der methods.
Reject empty OctKey. Full Changelog : 1.6.7...1.6.8
Full Changelog: 1.6.7...1.6.8
jws : Validate payload size for b64=false - by @lepture (4d4ea)
No significant changes View changes on GitHub
No significant changes
jwe : Remove InvalidCEKLengthError - by @lepture (8aeb1)
Released on April 13, 2026
JWE: remove InvalidCEKLengthError.
JWK: fix ECKey serialization.
jwe: Set max value for p2c - by @lepture (696a9)
Class does not need to inherit object - by @lepture (4a9be)
Released on February 16, 2026
JWE: Auto add kid to recipient.
JWE: Use DeflateZipModel.MAX_SIZE to determine size limit.
Remove duplicate code - by @lepture (2c2ca)
Released on December 30, 2025
Deprecate InvalidTokenError, please use InvalidClaimError instead.
Convert ExpiredTokenError to inherit from ClaimError.
Improve on type hints.
Remove backend parameter, it is deprecated - by @lepture (e10e1)
Released on December 14, 2025
filter_algorithms names defaults to all algorithms. 79.
Replace JWSRegistry.guess_alg with JWSRegistry.guess_algorithm.
filter_algorithms and guess_alg supports KeySet objects. 81.
Improve generate_private_key method on Key's binding class.
Raise InvalidKeyCurveError when generating ECKey with an invalid curve.
Allow import key from cryptography native key types.
Add ECKey.derive_key and OKPKey.derive_key class methods.
jwa: Add Ed25519 and Ed448 algorithms for JWS - by @lepture (9e274)
Released on November 30, 2025
Add Ed25519 and Ed448 algorithms per rfc9864, via 76.
Marked EdDSA algorithm as deprecated per rfc9864, via 76.
Add parameter default_type for jwt.encode method.
Check ssh_type and cryptography key types in bindings - by @lepture (45cd6)
Released on November 19, 2025
Import bytes or str keys without specified key type, via 73.
Remove raw value from ExceededSizeError - by @lepture (63932)
Released on November 17, 2025
Remove the original content from ExceededSizeError.
errors: Add a base ClaimError - by @lepture (d91b3)
Released on November 5, 2025
Add a base ClaimError for catching JWT claim validation errors.
Show security warnings when importing weak OctKey and RSAKey.
Remove deprecated modules - by @lepture (ce206)
Released on October 9, 2025
Improvements on type hints.
Add python 3.14 support.
Breaking changes:
Remove deprecated (since 1.2.0) rfcXXXX modules.
Rename jwt.ClaimsRegistry to jwt.BaseClaimsRegistry.
Remove raw value from ExceededSizeError - by @lepture (673c8)
Released on November 18, 2025
Remove the original content from ExceededSizeError.
Use explicit type for json_b64encode and json_b64decode - by @lepture (61a17)
Released on September 21, 2025
Add size limit for deserializing JWS content.
Add size limit for decrypting JWE content.
Reject crit header in unprotected headers - by @lepture (10d9d)
Released on September 15, 2025
Reject crit header in unprotected headers.
Check header in crit is supported - by @lepture (70085)
Released on September 4, 2025
Returns the first key when multiple keys found in a key set.
Validate if a "crit" header is supported in the registry.
Prevent unprotected header overwriting protected header - by @lepture (28319)
Released on August 27, 2025
Fix jws.deserialize_json and jwe.decrypt_json, preventing unprotected header overwriting protected header.
Remove python 3.8 support. - by @lepture (19666)
Released on August 25, 2025
Exporting all algorithms in joserfc.jwa module.
Allow reusing JWTClaimsRegistry instance, via 68.
Added claim attribute on claim errors, via 69.
Added JWSRegistry.guess_alg method, via 49.
Breaking changes:
Remove Python 3.8 support.
Rename JWS and JWE Algorithm model class names to prevent name conflicts.
Support partial list matching in JWTClaimRegistry.validate, similar to aud claim logic - by @feteu in https://github.com/authlib/joserfc/issues/63 (62
Released on July 14, 2025
Fix typo for function name of Chacha20-Poly1305 registration, via 67.
Add claims partial list matching in JWTClaimRegistry.validate, via 63.
Move RSA1_5 security warning to its instance - by @lepture (1e4d1)
Released on July 10, 2025
Improve type hints on JWK module:
Overload type hints on jwk.import_key and jwk.generate_key.
Return correct types on OctKey.import_key, RSAKey.import_key, and etc.
Guess key with "alg" and "use" parameters.
Remove deprecated guessing key from bytes and string - by @lepture (fc343)
Released on July 7, 2025
Added rfc9278 JWK Thumbprint URI thumbprint_uri.
Show security warnings for none and RSA1_5 algorithms.
Show security warnings for OctKey.generate_key and RSAKey.generate_key. when key size is too short, per NIST SP 800-131A.
Breaking changes:
Enable "RFC7797" by default, use the joserfc.jws module directly.
Use joserfc.jws.serialize_compact instead of joserfc.rfc7797.serialize_compact
Use joserfc.jws.deserialize_compact instead of joserfc.rfc7797.deserialize_compact
Use joserfc.jws.serialize_json instead of joserfc.rfc7797.serialize_json
Use joserfc.jws.deserialize_json instead of joserfc.rfc7797.deserialize_json
Convert joserfc.rfcXXXX to private modules joserfc._rfcXXXX.
Use ECKey.binding.register_curve to register new supported curves. - by @lepture (04dd9)
ECKey.binding.register_curve to register new supported curves. - by @lepture <samp>(04dd9)</samp>__eq__ for Key and KeySet - by @lepture <samp>(2ebe3)</samp>InvalidHeaderValueError in registry header validation - by @lepture in https://github.com/authlib/joserfc/issues/47 <samp>(79826)</samp>import_key and generate_key methods - by @lepture <samp>(48a3a)</samp>KeyBase and GuestProtocol to __all__ - by @nsmithuk <samp>(b9ec7)</samp>Released on May 24, 2025
Use "import as" to prioritize the modules for editors.
Added parameter encoder_cls for jwt.encode and decoder_cls for jwt.decode.
Added none algorithm for JWS.
Added jwk.import_key and jwk.generate_key aliases.
Breaking changes:
Use ECKey.binding.register_curve to register new supported curves.
Use UnsupportedAlgorithmError instead of ValueError in JWS/JWE registry.
Use MissingKeyTypeError and InvalidKeyIdError for errors in JWK.
Use UnsupportedHeaderError, MissingHeaderError, and MissingCritHeaderError for header validation.
Respect RFC6749 character set in error descriptions.
Use secrets module to generate random bytes - by @lepture (a44cd)
Released on February 28, 2025
Use secrets module to generate random bytes.
Use warnings for possible unsafe OctKey instead of raising error, via 32.
Allow sha256, sha384, sha512 hash functions in thumbprint, via #30 - by @lepture in https://github.com/authlib/joserfc/issues/30 (d6a48)
Released on February 6, 2025
Allow using sha256, sha384, sha512 hash functions in thumbprint (RFC7638).
Support import key from a certificate pem file - by @lepture (bfff3)
Released on January 20, 2025
Support import key from a certificate pem file.
Throw an error on non-valid base64 strings - by @viccie30 (2b959)
Released on December 3, 2024
Throw an error on non-valid base64 strings.
types: Added boolean types for registry value and values options added tests for boolean value and values in registry - by @stormcow (5e58b)
jwe: Limit DEF decompress size to 250k bytes - by @lepture (e9df3)
Released on June 15, 2024
Limit DEF decompress size to 250k bytes.
Fix claims validation, via 23.
jwt: No need to verify typ header value - by @lepture (90526)
Released on June 4, 2024
Remove validating typ header with jwt.decode method.
jwe: Allow verify only one recipient - by @lepture (79d30)
Released on June 4, 2024
jwe.decrypt_json allows to verify only one recipient.
Prevent OctKey to import ssh-dss.
Deprecate use of string and bytes as key.
Jwt encode and decode methods only works for JWS by default - by @lepture (29d39)
Released on May 13, 2024
Change jwt.encode and jwt.decode to use JWS by default.
Callable key can return str, bytes, Key, and KeySet - by @lepture (43be0)
allow_blank - by @lepture <samp>(2f7a5)</samp>Released on November 16, 2023
Use os.urandom for OctKey.generate_key.
Add allow_blank for JWTClaimsRegistry.
Improve callable key for ~jwk.guess_key.
jwk: Add ensure_kid method on key model, add auto_kid when generate key - by @lepture (3a49e)
Released on September 06, 2023
Add ensure_kid method on key models.
Add auto_kid parameter on key model .generate_key method.
Improvements on type hints
Clean useless except of binascii.Error - by @lepture (c98cf)
exchange_derive_key - by @lepture <samp>(fa291)</samp>Released on August 14, 2023
Add "iat" claims validation in JWT.
Add __bool__ magic method on jwk.KeySet.
Raise InvalidExchangeKeyError for exchange_derive_key on Curve key.
Improvements on type hints
jwe: Split JSONEncryption to GeneralJSONEncryption and FlattenedJSONEncryption - by @lepture (76912)
Released on July 20, 2023
Huge improvements on type hints, via Viicos.
Do not mutate the header when jwt.encode, via 6.
Register algorithms with their matched key types on key set.
Improve error handling, raise proper errors.
Breaking changes:
jws.JSONSignature is replaced by jws.GeneralJSONSignature and jws.FlattenedJSONSignature.
jwe.JSONEncryption is replaced by jwe.GeneralJSONEncryption and jwe.FlattenedJSONEncryption.
jwk: Rename exchange_shared_key to exchange_derive_key - by @lepture (2b00e)
Released on July 12, 2023
Add RFC7797 JSON Web Signature (JWS) Unencoded Payload Option
Fix decrypt_json when there is no encrypted_key
Rename JWE CompleteJSONSerialization to GeneralJSONSerialization
Rename JSONEncryption.flatten to .flattened
Load and dump RSA, EC, and OKP key with password
Rename Curve key method: exchange_shared_key to exchange_derive_key
Change JWSRegistry and JWERegistry parameters - by @lepture (8707e)
Released on July 6, 2023
Change options to parameters for JWK methods
Change JWSRegistry and JWERegistry parameters
Guess sender_key from JWKs in JWE
Add importing key from DER encoding bytes
Fix JWS JSON serialization when members have only unprotected headers
Check key type before processing algorithms of JWS and JWE
Remove useless generate_token function - by @lepture (04ded)
Released on June 29, 2023
Return str instead of bytes for JWS and JWE serializations
Add a detach_content method for JWS
Remove jwt.extract method, because extract won't work for JWE
Add JWKRegistry for JWK
Update JSONEncryption.add_recipient parameters
Export register methods for JWE drafts
api: Design jws, jwe, jwk, jwt interface - by @lepture (ea3b0)
Released on March 5, 2023 Initial release.
Released on March 5, 2023
Initial release.
Your coding agent can read these notes before it upgrades. Set up the MCP server →