OSS TanbouSign in with GitHub

handle JWT, JWS, JWE, JWK, and JWKS with a zero-dependency Web-standard JOSE library

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
7,815
Primary language
TypeScript
License
MIT
Repository last updated
Oct 1, 2026
On this page

Overview

jose is a JavaScript library for JOSE standards including JWT, JWS, JWE, JWK, and JWKS. It runs across Node.js, browsers, Cloudflare Workers, Deno, Bun, and other Web-interoperable runtimes and ships as dependency-free tree-shakeable ESM.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Sign and verify JWTs with claims validation

SignJWT and jwtVerify cover token creation, signature verification, and claims validation, with local and remote JWKS support for key resolution.

Sources: [1]

Use JWS, JWE, JWK/JWKS, and key import/export through one library

It supports Compact, Flattened, and General JWS/JWE forms plus JWK and PEM/SPKI/X.509/PKCS#8 import/export and key or secret generation.

Sources: [1]

Best fit

Fits Next.js and edge runtimes that need shared token-processing code

Its WebCrypto-oriented design makes it useful when Node servers and edge/worker runtimes should share JWT and JWKS logic.

Sources: [1][3]

Before adoption

Decoding is not verification, so use verify APIs at authentication boundaries

Reading a JWT payload does not validate its signature or claims. Authentication and authorization decisions should verify algorithms, issuer, audience, expiration, and other required claims.

Sources: [1]

Version 6 is ESM-oriented, so confirm bundler and runtime compatibility

Version 6.2.12 ships tree-shakeable ESM and Web-runtime exports. Legacy CommonJS-heavy applications should verify their import path and bundler behavior.

Sources: [3]

Official sources

  1. [1]jose v6.2.12 README(2026-10-06)
  2. [2]jose v6.2.12 release(2026-10-06)
  3. [3]jose v6.2.12 package metadata(2026-10-06)
Supplemental curator note

It fits shared JWT/JWKS logic across Next.js server and edge runtimes. Do not confuse decoding with verification; validate algorithms, issuer, audience, and claims at security boundaries.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/panva/jose.git
  2. 2

    Enter the repository

    cd jose
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

7,815 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
8
Open PRs
0

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • jose
  • jwa
  • jwe
  • jwk
  • jws
  • jwks
  • jwt
  • jsonwebtoken
  • deno
  • node
  • browser
  • cloudflare-workers
Stars
7,815
Forks
377
Watchers
39
Open issues
0
Contributors
35
Owner type
User
Primary language
TypeScript
License
MIT
Repository last updated
Oct 1, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?