On this page
Overview
jose is a JavaScript library for JOSE standards including JWT, JWS, JWE, JWK, and JWKS. It runs across Node.js, browsers, Cloudflare Workers, Deno, Bun, and other Web-interoperable runtimes and ships as dependency-free tree-shakeable ESM.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Sign and verify JWTs with claims validation
SignJWT and jwtVerify cover token creation, signature verification, and claims validation, with local and remote JWKS support for key resolution.
Sources: [1]
Use JWS, JWE, JWK/JWKS, and key import/export through one library
It supports Compact, Flattened, and General JWS/JWE forms plus JWK and PEM/SPKI/X.509/PKCS#8 import/export and key or secret generation.
Sources: [1]
Best fit
Before adoption
Decoding is not verification, so use verify APIs at authentication boundaries
Reading a JWT payload does not validate its signature or claims. Authentication and authorization decisions should verify algorithms, issuer, audience, expiration, and other required claims.
Sources: [1]
Version 6 is ESM-oriented, so confirm bundler and runtime compatibility
Version 6.2.12 ships tree-shakeable ESM and Web-runtime exports. Legacy CommonJS-heavy applications should verify their import path and bundler behavior.
Sources: [3]
Official sources
- [1]jose v6.2.12 README(2026-10-06)
- [2]jose v6.2.12 release(2026-10-06)
- [3]jose v6.2.12 package metadata(2026-10-06)
Supplemental curator note
It fits shared JWT/JWKS logic across Next.js server and edge runtimes. Do not confuse decoding with verification; validate algorithms, issuer, audience, and claims at security boundaries.
Try it in 3 steps
- 1
Get the source
git clone --depth 1 https://github.com/panva/jose.git - 2
Enter the repository
cd jose - 3
Check the official steps
Continue with the commands in the README Installation, Quick Start, or Getting Started section.
find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Growth
Growth trends · Last 30 days
7,815 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 8
- Open PRs
- 0
Development activity is still being collected.
Built with
Categories and tags
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- jose
- jwa
- jwe
- jwk
- jws
- jwks
- jwt
- jsonwebtoken
- deno
- node
- browser
- cloudflare-workers
- Stars
- 7,815
- Forks
- 377
- Watchers
- 39
- Open issues
- 0
- Contributors
- 35
- Owner type
- User
- Primary language
- TypeScript
- License
- MIT
- Repository last updated
- Oct 1, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Stripe Node.js Library4,522 Stars
3 shared tag(s) · 2 shared category(s) · Same language
Call Stripe APIs from server-side JavaScript/TypeScript with typed resources, retries, and webhook helpers
TypeScript - ts-rest3,338 Stars
3 shared tag(s) · 2 shared category(s) · Same language
share REST contracts for end-to-end type safety across clients, servers, and OpenAPI
TypeScript - Axios109,303 Stars
3 shared tag(s) · 2 shared category(s)
Share interceptors, adapters, timeouts, and cancellation across browser and Node.js HTTP requests
JavaScript - Unkey5,456 Stars
3 shared tag(s) · 2 shared category(s)
manage API keys, rate limits, RBAC, and gateway policy on one API platform
Go - Supabase111,098 Stars
3 shared tag(s) · 1 shared category(s) · Same language
Build on Postgres with integrated Auth, REST/GraphQL APIs, Realtime, Storage, and Functions
TypeScript - Ky17,104 Stars
3 shared tag(s) · 1 shared category(s) · Same language
extend Fetch API with concise retries, timeouts, hooks, and JSON handling
TypeScript
Report incorrect information
Tell us if any listing information is incorrect or outdated.