All notable changes to this project will be documented in this file. This project adheres to Semantic Versioning.
- Accept trailing Base64URL
=padding when decoding JWS segments, so tokens issued by AWS ALB and similar systems verify instead of raisingDecodeError: Invalid crypto padding. Non-alphabet junk such as!!!!remains rejected (#1209).
- Wrap recursion errors from deeply nested JWT payloads in
DecodeErrorinstead of exposing a rawRecursionError.
- Support Python 3.15 by @kytta in #1202
JWKSetCachenow stores the parsedPyJWKSetrather than the raw JWKS payload, so a cache hit no longer re-parses every key.JWKSetCache.put()accepts either form and raisesPyJWKSetErrorfor anything else. As a result,PyJWKClient.get_jwk_set()returns the samePyJWKSetinstance for as long as it stays cached, rather than a freshly built one per call in #1208PyJWKClient.fetch_data()now raisesPyJWKClientError("The JWKS endpoint did not return a JSON object")when the endpoint response is not a JSON object, instead of returning it forget_jwk_set()to reject. Callers reaching the JWKS throughget_jwk_set()see the same error as before in #1208
- Return cached
PyJWKSetvalues fromPyJWKClient.get_jwk_set()instead of raisingPyJWKClientError("The JWKS endpoint did not return a JSON object").JWKSetCache.put()documentsPyJWKSetas the cached value, so callers pre-populating the cache to avoid a network round-trip could not read it back in #914 and #1208 PyJWKClient.get_jwk_set()now caches the key set it returns, so afetch_data()override that filters or transforms the JWKS is no longer undone by the next cache hit in #1208- Raise the documented
PyJWTErrorsubclass instead of leaking aTypeErrorwhen theexp,nbf, oriatclaim decodes to a non-numeric, non-string value such as a list, dict, ornull. - Reject OKP JWK private keys when their public
xcomponent does not match the privatedcomponent. - Treat malformed JWK Set members as unusable keys rather than letting
AttributeErrororTypeErrorescapePyJWKSet. A member that is not a JSON object is skipped, a key whose components have the wrong type raisesInvalidKeyErrorand is skipped, and a set left with no usable keys raisesPyJWKSetError. A single bad entry no longer fails an otherwise usable JWK Set in #1208 - Wrap
http.client.HTTPException(e.g.IncompleteReadfrom a truncated response) inPyJWKClient.fetch_dataasPyJWKClientConnectionError, matching the other network failure modes the method already documents.
- Harden HMAC key validation against public-key material supplied as JWK, JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See GHSA-r6x4-923q-g947, GHSA-ffc3-869f-jxw9, GHSA-p4g4-x82p-q773, and GHSA-w2cx-738m-mc7w.
- Reject automatic redirects when
PyJWKClientfetches a JWKS, preventing redirected destinations from being treated as trusted key sources. See GHSA-9v7f-9g4p-ffgj. - Limit repeated JWKS refreshes caused by unknown key IDs while preserving normal key-rotation behavior. See GHSA-2gx3-rcp4-g85q.
- Handle deeply nested and malformed JWS/JWK input without uncaught recursion errors or whole-set parsing failures. See GHSA-8wjv-2p76-3863 and GHSA-w6j9-cwv2-h6wq.
- Enforce compact JWS encoding rules during decoding. See GHSA-hxm8-2xgr-2p9m.
- Reject detached-payload arguments for attached JWS inputs. Thanks to @xclow3n for reporting this behavior; fixed in commit 37b54877.
- Apply HMAC key validation consistently when keys are loaded through
PyJWKandPyJWKClient. See GHSA-pxh4-856f-4h89. - Reject empty HMAC keys when represented as JWKs. See GHSA-pxh4-856f-4h89.
- Reject JWK JSON documents passed as raw HMAC secrets in
HMACAlgorithm.prepare_keyto close an algorithm-confusion gap that the existing PEM/SSH guard did not cover. Reported by @aradona91 in GHSA-xgmm-8j9v-c9wx. - Bind the JWT header
algtoPyJWK.algorithm_nameduring verification so the caller'salgorithms=[...]allow-list cannot be bypassed when decoding with aPyJWK/PyJWKClientkey. Reported by @sushi-gif in GHSA-jq35-7prp-9v3f. - Reject non-
http(s)URI schemes inPyJWKClientso attacker- influenced URIs cannot read local files or reach unintended schemes via urllib's defaultfile:///ftp:///data:handlers. Reported by @KEIJOT in GHSA-993g-76c3-p5m4. - Preserve the cached JWK Set on fetch errors in
PyJWKClient.fetch_data. The previousfinally-blockput(None)pattern cleared the cache on any transient outage, turning one bad JWKS request into application- wide auth failure. Reported by @eddieran in GHSA-fhv5-28vv-h8m8. - Skip the unconditional base64 decode of the compact-form payload segment
when
b64=falseis set in the protected header, and require that segment to be empty (RFC 7515 Appendix F detached form). Closes an unauthenticated DoS amplifier. Reported by @thesmartshadow in GHSA-w7vc-732c-9m39.
- Reject empty HMAC keys outright in
HMACAlgorithm.prepare_keywithInvalidKeyErrorinstead of accepting them with only a warning. Thanks to @SnailSploit and @spartan8806 for independently flagging the footgun. - Forward per-call
options(includingenforce_minimum_key_length) fromPyJWT.decodethrough toPyJWS._verify_signatureso the option actually takes effect when set at the call site rather than only on thePyJWTinstance. Thanks to @WLUB for the report. - RFC 7797 §3 compliance for
b64=false: the encoder now auto-adds"b64"to thecritheader parameter, and the decoder rejects tokens that setb64=falsewithout listing it incrit. Thanks to @MachineLearning-Nerd for the report.
- Migrate the
dev,docs, andtestspackage extras to dependency groups by @kurtmckee in #1152
- Add missing
typing_extensionsdependency for Python < 3.11 in #1150
- Annotate PyJWKSet.keys for pyright by @tamird in #1134
- Close
HTTPErrorresponse to preventResourceWarningon Python 3.14 by @veeceey in #1133 - Do not keep
algorithmsdict in PyJWK instances by @akx in #1143 - Validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. by @dmbs335 in GHSA-752w-5fwx-jx9f
- Use PyJWK algorithm when encoding without explicit algorithm in #1148
- Docs: Add
PyJWKClientAPI reference and document the two-tier caching system (JWK Set cache and signing key LRU cache).
- Enforce ECDSA curve validation per RFC 7518 Section 3.4.
- Fix build system warnings by @kurtmckee in #1105
- Validate key against allowed types for Algorithm family in #964
- Add iterator for JWKSet in #1041
- Validate iss claim is a string during encoding and decoding by @pachewise in #1040
- Improve typing/logic for options in decode, decode_complete by @pachewise in #1045
- Declare float supported type for lifespan and timeout by @nikitagashkov in #1068
- Fix
SyntaxWarnings/DeprecationWarnings caused by invalid escape sequences by @kurtmckee in #1103 - Development: Build a shared wheel once to speed up test suite setup times by @kurtmckee in #1114
- Development: Test type annotations across all supported Python versions, increase the strictness of the type checking, and remove the mypy pre-commit hook by @kurtmckee in #1112
- Support Python 3.14, and test against PyPy 3.10 and 3.11 by @kurtmckee in #1104
- Development: Migrate to
buildto test package building in CI by @kurtmckee in #1108 - Development: Improve coverage config and eliminate unused test suite code by @kurtmckee in #1115
- Docs: Standardize CHANGELOG links to PRs by @kurtmckee in #1110
- Docs: Fix Read the Docs builds by @kurtmckee in #1111
- Docs: Add example of using leeway with nbf by @djw8605 in #1034
- Docs: Refactored docs with
autodoc; addedPyJWSandjwt.algorithmsdocs by @pachewise in #1045 - Docs: Documentation improvements for "sub" and "jti" claims by @cleder in #1088
- Development: Add pyupgrade as a pre-commit hook by @kurtmckee in #1109
- Add minimum key length validation for HMAC and RSA keys (CWE-326).
Warns by default via
InsecureKeyLengthWarningwhen keys are below minimum recommended lengths per RFC 7518 Section 3.2 (HMAC) and NIST SP 800-131A (RSA). Passenforce_minimum_key_length=Truein options toPyJWTorPyJWSto raiseInvalidKeyErrorinstead. - Refactor
PyJWTto own an internalPyJWSinstance instead of calling globalapi_jwsfunctions.
- Prevent partial matching of iss claim by @fabianbadoi in GHSA-75c5-xw7c-p5pm
Remove algorithm requirement from JWT API, instead relying on JWS API for enforcement, by @luhn in #975
Use
Sequencefor parameter types rather thanListwhere applicable by @imnotjames in #970Add JWK support to JWT encode by @luhn in #979
Encoding and decoding payloads using the none algorithm by @jpadilla in #c2629f6
Before:
>>> import jwt >>> jwt.encode({"payload": "abc"}, key=None, algorithm=None)
After:
>>> import jwt >>> jwt.encode({"payload": "abc"}, key=None, algorithm="none")
Added validation for 'sub' (subject) and 'jti' (JWT ID) claims in tokens by @Divan009 in #1005
Refactor project configuration files from
setup.cfgtopyproject.tomlby @cleder in #995Ruff linter and formatter changes by @gagandeepp in #1001
Drop support for Python 3.8 (EOL) by @kkirsche in #1007
- Encode EC keys with a fixed bit length by @etianen in #990
- Add an RTD config file to resolve Read the Docs build failures by @kurtmckee in #977
- Docs: Update
iatexception docs by @pachewise in #974 - Docs: Fix
decode_completescope and algorithms by @RbnRncn in #982 - Fix doctest for
docs/usage.rstby @pachewise in #986 - Fix
test_utils.pynot to xfail by @pachewise in #987 - Docs: Correct jwt.decode audience param doc expression by @peter279k in #994
- Add support for python 3.13 by @hugovk in #972
- Create SECURITY.md by @auvipy and @jpadilla in #973
- Docs: Add PS256 encoding and decoding usage by @peter279k in #992
- Docs: Add API docs for PyJWK by @luhn in #980
- Docs: Add EdDSA algorithm encoding/decoding usage by @peter279k in #993
- Include checkers and linters for
pyproject.tomlinpre-commitby @cleder in #1002 - Docs: Add ES256 decoding usage by @Gautam-Hegde in #1003
- Drop support for Python 3.7 (EOL) by @hugovk in #910
- Allow JWT issuer claim validation to accept a list of strings too by @mattpollak in #913
- Fix unnecessary string concatenation by @sirosen in #904
- Fix docs for
jwt.decode_completeto includestrict_audoption by @woodruffw in #923 - Fix docs step by @jpadilla in #950
- Fix: Remove an unused variable from example code block by @kenkoooo in #958
- Add support for Python 3.12 by @hugovk in #910
- Improve performance of
is_ssh_key+ add unit test by @bdraco in #940 - Allow
jwt.decode()to accept a PyJWK object by @luhn in #886 - Make
algorithm_nameattribute available on PyJWK by @luhn in #886 - Raise
InvalidKeyErroron invalid PEM keys to be compatible with cryptography 42.x.x by @CollinEMac in #952 - Raise an exception when required cryptography dependency is missing by @tobloef in #963
- Update python version test matrix by @auvipy in #895
- Add
strict_audas an option tojwt.decodeby @woodruffw in #902 - Export PyJWKClientConnectionError class by @daviddavis in #887
- Allows passing of ssl.SSLContext to PyJWKClient by @juur in #891
- Changed the error message when the token audience doesn't match the expected audience by @irdkwmnsb #809
- Improve error messages when cryptography isn't installed by @Viicos in #846
- Make Algorithm an abstract base class by @Viicos in #845
- ignore invalid keys in a jwks by @timw6n in #863
- Add classifier for Python 3.11 by @eseifert in #818
- Fix
_validate_iatvalidation by @Viicos in #847 - fix: use datetime.datetime.timestamp function to have a milliseconds by @daillouf #821
- docs: correct mistake in the changelog about verify param by @gbillig in #866
- Add
compute_hash_digestas a method ofAlgorithmobjects, which uses the underlying hash algorithm to compute a digest. If there is no appropriate hash algorithm, aNotImplementedErrorwill be raised in #775 - Add optional
headersargument toPyJWKClient. If provided, the headers will be included in requests that the client uses when fetching the JWK set by @thundercat1 in #823 - Add PyJWT._{de,en}code_payload hooks by @akx in #829
- Add sort_headers parameter to api_jwt.encode by @evroon in #832
- Make mypy configuration stricter and improve typing by @akx in #830
- Add more types by @Viicos in #843
- Add a timeout for PyJWKClient requests by @daviddavis in #875
- Add client connection error exception by @daviddavis in #876
- Add complete types to take all allowed keys into account by @Viicos in #873
- Add as_dict option to Algorithm.to_jwk by @fluxth in #881
- bump up cryptography >= 3.4.0 by @jpadilla in #807
- Remove types-cryptography from crypto extra by @lautat in #805
- Invalidate token on the exact second the token expires #797
- fix: version 2.5.0 heading typo by @c0state in #803
- Adding validation for issued_at when iat > (now + leeway) as ImmatureSignatureError by @sriharan16 in #794
- Skip keys with incompatible alg when loading JWKSet by @DaGuich in #762
- Remove support for python3.6 by @sirosen in #777
- Emit a deprecation warning for unsupported kwargs by @sirosen in #776
- Remove redundant wheel dep from pyproject.toml by @mgorny in #765
- Do not fail when an unusable key occurs by @DaGuich in #762
- Update audience typing by @JulianMaurin in #782
- Improve PyJWKSet error accuracy by @JulianMaurin in #786
- Mypy as pre-commit check + api_jws typing by @JulianMaurin in #787
- Adjust expected exceptions in option merging tests for PyPy3 by @mgorny in #763
- Fixes for pyright on strict mode by @brandon-leapyear in #747
- docs: fix simple typo, iinstance -> isinstance by @timgates42 in #774
- Fix typo: priot -> prior by @jdufresne in #780
- Fix for headers disorder issue by @kadabusha in #721
- Add to_jwk static method to ECAlgorithm by @leonsmith in #732
- Expose get_algorithm_by_name as new method by @sirosen in #773
- Add type hints to jwt/help.py and add missing types dependency by @kkirsche in #784
- Add cacheing functionality for JWK set by @wuhaoyujerry in #781
- [CVE-2022-29217] Prevent key confusion through non-blocklisted public key formats. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24
- Explicit check the key for ECAlgorithm by @estin in #713
- Raise DeprecationWarning for jwt.decode(verify=...) by @akx in #742
- Don't use implicit optionals by @rekyungmin in #705
- documentation fix: show correct scope for decode_complete() by @sseering in #661
- fix: Update copyright information by @kkirsche in #729
- Don't mutate options dictionary in .decode_complete() by @akx in #743
- Add support for Python 3.10 by @hugovk in #699
- api_jwk: Add PyJWKSet.__getitem__ by @woodruffw in #725
- Update usage.rst by @guneybilen in #727
- Docs: mention performance reasons for reusing RSAPrivateKey when encoding by @dmahr1 in #734
- Fixed typo in usage.rst by @israelabraham in #738
- Add detached payload support for JWS encoding and decoding by @fviard in #723
- Replace various string interpolations with f-strings by @akx in #744
- Update CHANGELOG.rst by @hipertracker in #751
- Revert "Remove arbitrary kwargs." #701
- Add exception chaining #702
- Assume JWK without the "use" claim is valid for signing as per RFC7517 #668
- Prefer headers["alg"] to algorithm in jwt.encode(). #673
- Fix aud validation to support {'aud': null} case. #670
- Make typ optional in JWT to be compliant with RFC7519. #644
- Remove upper bound on cryptography version. #693
- Add support for Ed448/EdDSA. #675
- Allow claims validation without making JWT signature validation mandatory. #608
- Remove padding from JWK test data. #628
- Make kty mandatory in JWK to be compliant with RFC7517. #624
- Allow JWK without alg to be compliant with RFC7517. #624
- Allow to verify with private key on ECAlgorithm, as well as on Ed25519Algorithm. #645
- Add caching by default to PyJWKClient #611
- Add missing exceptions.InvalidKeyError to jwt module __init__ imports #620
- Add support for ES256K algorithm #629
- Add from_jwk() to Ed25519Algorithm #621
- Add to_jwk() to Ed25519Algorithm #643
- Export PyJWK and PyJWKSet #652
- Rename CHANGELOG.md to CHANGELOG.rst and include in docs #597
- Fix from_jwk() for all algorithms #598
Python 3.5 is EOL so we decide to drop its support. Version 1.7.1 is
the last one supporting Python 3.0-3.5.
We've kept this around for a long time, mostly for environments that didn't allow installing cryptography.
Dropped the included cli entry point.
We no longer need to use mypy Python 2 compatibility mode (comments)
Tokens are returned as string instead of a byte string
Removed ExpiredSignature, InvalidAudience, and
InvalidIssuer. Use ExpiredSignatureError,
InvalidAudienceError, and InvalidIssuerError instead.
Use
jwt.decode(encoded, key, algorithms=["HS256"], options={"verify_exp": False})
instead.
Use jwt.decode(encoded, key, options={"verify_signature": False})
instead.
Example: jwt.decode(encoded, key, algorithms=["HS256"]).
For example, instead of
jwt.decode(encoded, key, algorithms=["HS256"], options={"require_exp": True}),
use
jwt.decode(encoded, key, algorithms=["HS256"], options={"require": ["exp"]}).
And the old v1.x syntax
jwt.decode(token, verify=False)
is now:
jwt.decode(jwt=token, key='secret', algorithms=['HS256'], options={"verify_signature": False})
Introduce PyJWK, PyJWKSet, and PyJWKClient.
import jwt
from jwt import PyJWKClient
token = "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6Ik5FRTFRVVJCT1RNNE16STVSa0ZETlRZeE9UVTFNRGcyT0Rnd1EwVXpNVGsxUWpZeVJrUkZRdyJ9.eyJpc3MiOiJodHRwczovL2Rldi04N2V2eDlydS5hdXRoMC5jb20vIiwic3ViIjoiYVc0Q2NhNzl4UmVMV1V6MGFFMkg2a0QwTzNjWEJWdENAY2xpZW50cyIsImF1ZCI6Imh0dHBzOi8vZXhwZW5zZXMtYXBpIiwiaWF0IjoxNTcyMDA2OTU0LCJleHAiOjE1NzIwMDY5NjQsImF6cCI6ImFXNENjYTc5eFJlTFdVejBhRTJINmtEME8zY1hCVnRDIiwiZ3R5IjoiY2xpZW50LWNyZWRlbnRpYWxzIn0.PUxE7xn52aTCohGiWoSdMBZGiYAHwE5FYie0Y1qUT68IHSTXwXVd6hn02HTah6epvHHVKA2FqcFZ4GGv5VTHEvYpeggiiZMgbxFrmTEY0csL6VNkX1eaJGcuehwQCRBKRLL3zKmA5IKGy5GeUnIbpPHLHDxr-GXvgFzsdsyWlVQvPX2xjeaQ217r2PtxDeqjlf66UYl6oY6AqNS8DH3iryCvIfCcybRZkc_hdy-6ZMoKT6Piijvk_aXdm7-QQqKJFHLuEqrVSOuBqqiNfVrG27QzAPuPOxvfXTVLXL2jek5meH6n-VWgrBdoMFH93QEszEDowDAEhQPHVs0xj7SIzA"
kid = "NEE1QURBOTM4MzI5RkFDNTYxOTU1MDg2ODgwQ0UzMTk1QjYyRkRFQw"
url = "https://dev-87evx9ru.auth0.com/.well-known/jwks.json"
jwks_client = PyJWKClient(url)
signing_key = jwks_client.get_signing_key_from_jwt(token)
data = jwt.decode(
token,
signing_key.key,
algorithms=["RS256"],
audience="https://expenses-api",
options={"verify_exp": False},
)
print(data)- Add PyPy3 to the test matrix (#550) by @jdufresne
- Require tweak (#280) by @psafont
- Decode return type is dict[str, Any] (#393) by @jacopofar
- Fix linter error in test_cli (#414) by @jaraco
- Run mypy with tox (#421) by @jpadilla
- Document (and prefer) pyjwt[crypto] req format (#426) by @gthb
- Correct type for json_encoder argument (#438) by @jdufresne
- Prefer https:// links where available (#439) by @jdufresne
- Pass python_requires argument to setuptools (#440) by @jdufresne
- Rename [wheel] section to [bdist_wheel] as the former is legacy (#441) by @jdufresne
- Remove setup.py test command in favor of pytest and tox (#442) by @jdufresne
- Fix mypy errors (#449) by @jpadilla
- DX Tweaks (#450) by @jpadilla
- Add support of python 3.8 (#452) by @Djailla
- Fix 406 (#454) by @justinbaur
- Add support for Ed25519 / EdDSA, with unit tests (#455) by @Someguy123
- Remove Python 2.7 compatibility (#457) by @Djailla
- Fix simple typo: encododed -> encoded (#462) by @timgates42
- Enhance tracebacks. (#477) by @JulienPalard
- Simplify
python_requires(#478) by @michael-k - Document top-level .encode and .decode to close #459 (#482) by @dimaqq
- Improve documentation for audience usage (#484) by @CorreyL
- Correct README on how to run tests locally (#489) by @jdufresne
- Fix
tox -e lintwarnings and errors (#490) by @jdufresne - Run pyupgrade across project to use modern Python 3 conventions (#491) by @jdufresne
- Add Python-3-only trove classifier and remove "universal" from wheel (#492) by @jdufresne
- Emit warnings about user code, not pyjwt code (#494) by @mgedmin
- Move setup information to declarative setup.cfg (#495) by @jdufresne
- CLI options for verifying audience and issuer (#496) by @GeoffRichards
- Specify the target Python version for mypy (#497) by @jdufresne
- Remove unnecessary compatibility shims for Python 2 (#498) by @jdufresne
- Setup GH Actions (#499) by @jpadilla
- Implementation of ECAlgorithm.from_jwk (#500) by @jpadilla
- Remove cli entry point (#501) by @jpadilla
- Expose InvalidKeyError on jwt module (#503) by @russellcardullo
- Avoid loading token twice in pyjwt.decode (#506) by @CaselIT
- Default links to stable version of documentation (#508) by @salcedo
- Update README.md badges (#510) by @jpadilla
- Introduce better experience for JWKs (#511) by @jpadilla
- Fix tox conditional extras (#512) by @jpadilla
- Return tokens as string not bytes (#513) by @jpadilla
- Drop support for legacy contrib algorithms (#514) by @jpadilla
- Drop deprecation warnings (#515) by @jpadilla
- Update Auth0 sponsorship link (#519) by @Sambego
- Update return type for jwt.encode (#521) by @moomoolive
- Run tests against Python 3.9 and add trove classifier (#522) by @michael-k
- Removed redundant
default_backend()(#523) by @rohitkg98 - Documents how to use private keys with passphrases (#525) by @rayluo
- Update version to 2.0.0a1 (#528) by @jpadilla
- Fix usage example (#530) by @nijel
- add EdDSA to docs (#531) by @CircleOnCircles
- Remove support for EOL Python 3.5 (#532) by @jdufresne
- Upgrade to isort 5 and adjust configurations (#533) by @jdufresne
- Remove unused argument "verify" from PyJWS.decode() (#534) by @jdufresne
- Update typing syntax and usage for Python 3.6+ (#535) by @jdufresne
- Run pyupgrade to simplify code and use Python 3.6 syntax (#536) by @jdufresne
- Drop unknown pytest config option: strict (#537) by @jdufresne
- Upgrade black version and usage (#538) by @jdufresne
- Remove "Command line" sections from docs (#539) by @jdufresne
- Use existing key_path() utility function throughout tests (#540) by @jdufresne
- Replace force_bytes()/force_unicode() in tests with literals (#541) by @jdufresne
- Remove unnecessary Unicode decoding before json.loads() (#542) by @jdufresne
- Remove unnecessary force_bytes() calls prior to base64url_decode() (#543) by @jdufresne
- Remove deprecated arguments from docs (#544) by @jdufresne
- Update code blocks in docs (#545) by @jdufresne
- Refactor jwt/jwks_client.py without requests dependency (#546) by @jdufresne
- Tighten bytes/str boundaries and remove unnecessary coercing (#547) by @jdufresne
- Replace codecs.open() with builtin open() (#548) by @jdufresne
- Replace int_from_bytes() with builtin int.from_bytes() (#549) by @jdufresne
- Enforce .encode() return type using mypy (#551) by @jdufresne
- Prefer direct indexing over options.get() (#552) by @jdufresne
- Cleanup "noqa" comments (#553) by @jdufresne
- Replace merge_dict() with builtin dict unpacking generalizations (#555) by @jdufresne
- Do not mutate the input payload in PyJWT.encode() (#557) by @jdufresne
- Use direct indexing in PyJWKClient.get_signing_key_from_jwt() (#558) by @jdufresne
- Split PyJWT/PyJWS classes to tighten type interfaces (#559) by @jdufresne
- Simplify mocked_response test utility function (#560) by @jdufresne
- Autoupdate pre-commit hooks and apply them (#561) by @jdufresne
- Remove unused argument "payload" from PyJWS.verifysignature() (#562) by @jdufresne
- Add utility functions to assist test skipping (#563) by @jdufresne
- Type hint jwt.utils module (#564) by @jdufresne
- Prefer ModuleNotFoundError over ImportError (#565) by @jdufresne
- Fix tox "manifest" environment to pass (#566) by @jdufresne
- Fix tox "docs" environment to pass (#567) by @jdufresne
- Simplify black configuration to be closer to upstream defaults (#568) by @jdufresne
- Use generator expressions (#569) by @jdufresne
- Simplify from_base64url_uint() (#570) by @jdufresne
- Drop lint environment from GitHub actions in favor of pre-commit.ci (#571) by @jdufresne
- [pre-commit.ci] pre-commit autoupdate (#572)
- Simplify tox configuration (#573) by @jdufresne
- Combine identical test functions using pytest.mark.parametrize() (#574) by @jdufresne
- Complete type hinting of jwks_client.py (#578) by @jdufresne
- Update test dependencies with pinned ranges
- Fix pytest deprecation warnings
- Remove CRLF line endings #353
- Update usage.rst #360
- Reverse an unintentional breaking API change to .decode() #352
- All exceptions inherit from PyJWTError #340
- Added section to usage docs for jwt.get_unverified_header() #350
- Update legacy instructions for using pycrypto #337
- Audience parameter throws
InvalidAudienceErrorwhen application does not specify an audience, but the token does. #336
- Dropped support for python 2.6 and 3.3 #301
- An invalid signature now raises an
InvalidSignatureErrorinstead ofDecodeError#316
- Fix over-eager fallback to stdin #304
- Audience parameter now supports iterables #306
- Increase required version of the cryptography package to >=1.4.0.
- Remove uses of deprecated functions from the cryptography package.
- Warn about missing
algorithmsparam todecode()only whenverifyparam isTrue#281
- Ensure correct arguments order in decode super call 7c1e61d
- Change optparse for argparse. #238
- Guard against PKCS1 PEM encoded public keys #277
- Add deprecation warning when decoding without specifying
algorithms#277 - Improve deprecation messages #270
- PyJWT.decode: move verify param into options #271
- Add support for ECDSA public keys in RFC 4253 (OpenSSH) format #244
- Renamed commandline script
jwttojwt-clito avoid issues with the script clobbering thejwtmodule in some circumstances. #187 - Better error messages when using an algorithm that requires the cryptography package, but it isn't available #230
- Tokens with future 'iat' values are no longer rejected #190
- Non-numeric 'iat' values now raise InvalidIssuedAtError instead of DecodeError
- Remove rejection of future 'iat' claims #252
- Add back 'ES512' for backward compatibility (for now) #225
- Fix incorrectly named ECDSA algorithm #219
- Fix rpm build #196
- Add JWK support for HMAC and RSA keys #202
- A PEM-formatted key encoded as bytes could cause a
TypeErrorto be raised #213
- Newer versions of Pytest could not detect warnings properly #182
- Non-string 'kid' value now raises
InvalidTokenError#174 jwt.decode(None)now gracefully fails withInvalidTokenError#183
- Exclude Python cache files from PyPI releases.
- Added new options to require certain claims (require_nbf,
require_iat, require_exp) and raise
MissingRequiredClaimErrorif they are not present. - If
audience=orissuer=is specified but the claim is not present,MissingRequiredClaimErroris now raised instead ofInvalidAudienceErrorandInvalidIssuerError
- ECDSA (ES256, ES384, ES512) signatures are now being properly serialized #158
- RSA-PSS (PS256, PS384, PS512) signatures now use the proper salt length for PSS padding. #163
- Added a new
jwt.get_unverified_header()to parse and return the header portion of a token prior to signature verification.
- Python 3.2 is no longer a supported platform. This version of Python is rarely used. Users affected by this should upgrade to 3.3+.
- Added back
verify_expiration=argument tojwt.decode()that was erroneously removed in v1.1.0.
- Refactored JWS-specific logic out of PyJWT and into PyJWS superclass. #141
verify_expiration=argument tojwt.decode()is now deprecated and will be removed in a future version. Use theoption=argument instead.
- Added support for PS256, PS384, and PS512 algorithms. #132
- Added flexible and complete verification options during decode. #131
- Added this CHANGELOG.md file.
- Deprecated usage of the .decode(..., verify=False) parameter.
- Fixed command line encoding. #128
- Include jwt/contrib' and jwt/contrib/algorithms` in setup.py so that they will actually be included when installing. 882524d
- Fix bin/jwt after removing jwt.header(). bd57b02
- Moved
jwt.api.headerout of the public API. #85 - Added README details how to extract public / private keys from an x509 certificate. #100
- Refactor api.py functions into an object (
PyJWT). #101 - Added support for PyCrypto and ecdsa when cryptography isn't available. #101