NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #570 most downloaded on PyPI
JOSE implementation in Python
Last release 1 years ago
28 May 2025
Ships unpredictably
gaps range from 5 weeks to 3.7 years
Most releases are documented
notes for 24 of 39 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
39 releases · first in 2015
Add RTD config file to silence emailed deprecation warnings
utc_now on module levelFix for CVE-2024-33664 - JWE limited to 250KiB
CryptographyAESKey::encrypt to generate 96 bit IVs for GCM blockOne column per quarter.
Fix deprecation warning from cryptography backend
~This will be the last release supporting Python 2.7, 3.5, and the PyCrypto backend.~ This will be the penultimate release supporting Python 2.7, 3.5,
to_dict output, which should always be JSON encodeable. #139 and #165
(fixes #127 and #137)Avoid using deprecated methods #85
JWT.decode() #76 (fixes #75)crytography dependency typo #94python setup.py test #97future dependency #134 (fixes #112)pytest.raises(message=...) #141dict payload #150access_token documentation #89dict for jwt.encode and jwt.decode #103CHANGELOG.rst #132 (fixes #99).travis.yml #135CHANGELOG.rst to CHANGELOG.md and update it #158Nothing published for this version
Move away from deprecated methods
As of 3.0.0, python-jose uses the pure python rsa package for signing and verifying RSA signatures by default.
Other backends can be used by installing python-jose with extras. Options include pycrypto, pycryptodome and cryptography. It is recommended that one of these options is used in production, as they will be much faster than the pure python rsa module.
The cryptography option is a good default.
Nothing published for this version
Bump the pycrpytodome dependency.
Bump the pycrpytodome dependency.
As of 2.0.0, python-jose uses pycrpytodome as the default signing backend for RSA functions.
As of 2.0.0, python-jose uses pycrpytodome as the default signing backend for RSA functions.
Other backends can be used by installing python-jose with extras. Options include pycrypto and cryptography.
Easier extending/replacing of key algorithms
Use constant time string comparisons for HMAC keys
Handle errors with lists of keys
## New Features - Support for Firebase certs
Allows multiple values for 'iss'
Support for at_hash verification
JWKs are now supported as first class objects.
Remove builtins dependency which broke AppEngine support
Allow users to validate a specific subject
Fix missing future dependency for python2.
Fix missing future dependency for python2.
My apologies for breaking 0.6.0.
Nothing published for this version
Handling signature verification errors with a better message.
Handling signature verification errors with a better message.
Nothing published for this version
Add custom headers support to jwt.encode
Add get_unverified_headers and get_unverified_claims methods to jws and jwt.
Add get_unverified_headers and get_unverified_claims methods to jws and jwt.
Nothing published for this version
python-jose is now python 3 compatible.
python-jose is now python 3 compatible.
Nothing published for this version
Nothing published for this version
ECDSA signatures are now supported.
ECDSA signatures are now supported.
Nothing published for this version
Nothing published for this version
Nothing published for this version
At this point, python-jose is ready to be used for JWS and JWT signing. The API and versioning are set and stable and predictable.
At this point, python-jose is ready to be used for JWS and JWT signing. The API and versioning are set and stable and predictable.
From here, the focus will be expanding algorithm usage to include ECSDA and RSA PSS signing.
After that, JWE and then JWK functionality.
This library will focus on using the PyCrypto library instead of moving to cryptography for easier Google App Engine support.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →