Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing " could close its own member and add members the application never set.
For example, calling Set with the name x":0,"admin produced a signed
token containing "admin":true. Every name now yields exactly one member,
and names that need no escaping serialize exactly as before. A name that is
not valid UTF-8 now fails serialization instead of being written raw.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
v4 has many incompatibilities with v3. To see the full list of differences between
v3 and v4, please read the Changes-v4.md file. Coding Agents should read MIGRATION.md
v4.0.0 - 19 Apr 2026
Initial v4 release. Major features:
Lighter: Core / Companion module separation. Less dependencies in core.
Faster: Use of generics and other optimizations make v4 2x~3x faster than before.
Quantum-Ready: ML-KEM and ML-DSA, HPKE (+Hybrid) are supported through companion modules.
See Changes-v4.md for a full set of Changes since v3.
Configuration
📅Schedule: (UTC)
Branch creation
At any time (no schedule defined)
Automerge
At any time (no schedule defined)
🚦Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕Ignore: Close this PR and you won't be reminded about this update again.
If you want to rebase/retry this PR, check this box
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/lestrrat-go/jwx/v3](https://github.com/lestrrat-go/jwx) | `v3.3.0` → `v4.5.0` |  |  |
---
### Release Notes
<details>
<summary>lestrrat-go/jwx (github.com/lestrrat-go/jwx/v3)</summary>
### [`v4.5.0`](https://github.com/lestrrat-go/jwx/releases/tag/v4.5.0)
[Compare Source](https://github.com/lestrrat-go/jwx/compare/v4.4.0...v4.5.0)
Security fix for GHSA-4cf7-xm37-g63h.
Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing
`"` could close its own member and add members the application never set.
For example, calling `Set` with the name `x":0,"admin` produced a signed
token containing `"admin":true`. Every name now yields exactly one member,
and names that need no escaping serialize exactly as before. A name that is
not valid UTF-8 now fails serialization instead of being written raw.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
For more detailed release notes, see [Changes](https://github.com/lestrrat-go/jwx/blob/v4.5.0/Changes).
#### What's Changed
- build(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2318](https://github.com/lestrrat-go/jwx/pull/2318)
- build(deps): bump github/codeql-action from 4.37.7 to 4.37.8 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2322](https://github.com/lestrrat-go/jwx/pull/2322)
- \[v4] deprecate AlgorithmsForKey, move to internal by [@​lestrrat](https://github.com/lestrrat) in [#​2325](https://github.com/lestrrat-go/jwx/pull/2325)
- \[v4] add jws.WithStrictECDSA sign option by [@​lestrrat](https://github.com/lestrrat) in [#​2327](https://github.com/lestrrat-go/jwx/pull/2327)
- \[v4] fix curve inference claim in docs by [@​lestrrat](https://github.com/lestrrat) in [#​2329](https://github.com/lestrrat-go/jwx/pull/2329)
- build(deps): bump github/codeql-action from 4.37.8 to 4.37.9 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2333](https://github.com/lestrrat-go/jwx/pull/2333)
- fix jwk.ParseKey generic guidance in guide skill by [@​lestrrat](https://github.com/lestrrat) in [#​2335](https://github.com/lestrrat-go/jwx/pull/2335)
- fix JWKS algorithm inference claim in guide by [@​lestrrat](https://github.com/lestrrat) in [#​2336](https://github.com/lestrrat-go/jwx/pull/2336)
- document exact alg match rule in guide by [@​lestrrat](https://github.com/lestrrat) in [#​2337](https://github.com/lestrrat-go/jwx/pull/2337)
- note RFC 9864 EdDSA deprecation in guide by [@​lestrrat](https://github.com/lestrrat) in [#​2338](https://github.com/lestrrat-go/jwx/pull/2338)
- drop nonexistent v3 and v2 plugin pointers by [@​lestrrat](https://github.com/lestrrat) in [#​2339](https://github.com/lestrrat-go/jwx/pull/2339)
- correct ML-DSA import panic claim in guide by [@​lestrrat](https://github.com/lestrrat) in [#​2340](https://github.com/lestrrat-go/jwx/pull/2340)
- add jwxfilter to guide companion table by [@​lestrrat](https://github.com/lestrrat) in [#​2341](https://github.com/lestrrat-go/jwx/pull/2341)
- build(deps): bump golang.org/x/crypto from 0.55.0 to 0.56.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2347](https://github.com/lestrrat-go/jwx/pull/2347)
- \[v4] escape JSON object member names on output by [@​lestrrat](https://github.com/lestrrat) in [#​2348](https://github.com/lestrrat-go/jwx/pull/2348)
**Full Changelog**: <https://github.com/lestrrat-go/jwx/compare/v4.4.0...v4.5.0>
### [`v4.4.0`](https://github.com/lestrrat-go/jwx/releases/tag/v4.4.0)
[Compare Source](https://github.com/lestrrat-go/jwx/compare/v4.3.0...v4.4.0)
For more detailed release notes, see [Changes](https://github.com/lestrrat-go/jwx/blob/v4.4.0/Changes).
#### What's Changed
- implement ML-DSA natively on Go 1.27 by [@​lestrrat](https://github.com/lestrrat) in [#​2309](https://github.com/lestrrat-go/jwx/pull/2309)
- use released Go 1.27 in CI by [@​lestrrat](https://github.com/lestrrat) in [#​2308](https://github.com/lestrrat-go/jwx/pull/2308)
- move ML-DSA primitives to dsig by [@​lestrrat](https://github.com/lestrrat) in [#​2310](https://github.com/lestrrat-go/jwx/pull/2310)
- generate ML-DSA from jwa/objects.yml by [@​lestrrat](https://github.com/lestrrat) in [#​2311](https://github.com/lestrrat-go/jwx/pull/2311)
- show both ML-DSA paths in the extensions doc by [@​lestrrat](https://github.com/lestrrat) in [#​2312](https://github.com/lestrrat-go/jwx/pull/2312)
- make GOEXPERIMENT conditional on Go 1.26 by [@​lestrrat](https://github.com/lestrrat) in [#​2313](https://github.com/lestrrat-go/jwx/pull/2313)
- point ML-DSA doc cache at generated jwa file by [@​lestrrat](https://github.com/lestrrat) in [#​2314](https://github.com/lestrrat-go/jwx/pull/2314)
- strip inherited jsonv2 on Go 1.27 by [@​lestrrat](https://github.com/lestrrat) in [#​2315](https://github.com/lestrrat-go/jwx/pull/2315)
**Full Changelog**: <https://github.com/lestrrat-go/jwx/compare/v4.3.0...v4.4.0>
### [`v4.3.0`](https://github.com/lestrrat-go/jwx/releases/tag/v4.3.0)
[Compare Source](https://github.com/lestrrat-go/jwx/compare/v4.2.0...v4.3.0)
For more detailed release notes, see [Changes](https://github.com/lestrrat-go/jwx/blob/v4.3.0/Changes).
#### What's Changed
- jwe: serialize the JSON "aad" member as BASE64URL(JWE AAD) by [@​sueun-dev](https://github.com/sueun-dev) in [#​2275](https://github.com/lestrrat-go/jwx/pull/2275)
- add JWE authenticated data option by [@​lestrrat](https://github.com/lestrrat) in [#​2277](https://github.com/lestrrat-go/jwx/pull/2277)
- build(deps): bump actions/stale from 10.4.0 to 11.0.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2281](https://github.com/lestrrat-go/jwx/pull/2281)
- build(deps): bump github/codeql-action from 4 to 4.37.3 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2284](https://github.com/lestrrat-go/jwx/pull/2284)
- build(deps): bump github/codeql-action from 4.37.3 to 4.37.4 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2286](https://github.com/lestrrat-go/jwx/pull/2286)
- build(deps): bump github/codeql-action from 4.37.4 to 4.37.5 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2291](https://github.com/lestrrat-go/jwx/pull/2291)
- build(deps): bump github/codeql-action from 4.37.5 to 4.37.6 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2294](https://github.com/lestrrat-go/jwx/pull/2294)
- fuzz every package, not just the module root by [@​lestrrat](https://github.com/lestrrat) in [#​2295](https://github.com/lestrrat-go/jwx/pull/2295)
- retry a fuzz target that fails with no crasher by [@​lestrrat](https://github.com/lestrrat) in [#​2296](https://github.com/lestrrat-go/jwx/pull/2296)
- build(deps): bump github/codeql-action from 4.37.6 to 4.37.7 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2303](https://github.com/lestrrat-go/jwx/pull/2303)
- build(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2302](https://github.com/lestrrat-go/jwx/pull/2302)
- fix build under Go 1.27 by [@​lestrrat](https://github.com/lestrrat) in [#​2304](https://github.com/lestrrat-go/jwx/pull/2304)
#### New Contributors
- [@​sueun-dev](https://github.com/sueun-dev) made their first contribution in [#​2275](https://github.com/lestrrat-go/jwx/pull/2275)
**Full Changelog**: <https://github.com/lestrrat-go/jwx/compare/v4.2.0...v4.3.0>
### [`v4.2.0`](https://github.com/lestrrat-go/jwx/releases/tag/v4.2.0)
[Compare Source](https://github.com/lestrrat-go/jwx/compare/v4.1.0...v4.2.0)
For more detailed release notes, see [Changes](https://github.com/lestrrat-go/jwx/blob/v4.2.0/Changes).
#### What's Changed
- docs: point jwkcache references to jwkfetch by [@​lestrrat](https://github.com/lestrrat) in [#​2245](https://github.com/lestrrat-go/jwx/pull/2245)
- chore: bump golangci-lint-action to 9.3.0 + sync action versions by [@​lestrrat](https://github.com/lestrrat) in [#​2246](https://github.com/lestrrat-go/jwx/pull/2246)
- fix misspellings in code comments by [@​lestrrat](https://github.com/lestrrat) in [#​2248](https://github.com/lestrrat-go/jwx/pull/2248)
- build(deps): bump golang.org/x/crypto from 0.49.0 to 0.52.0 in /internal/jwxcodegen by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2256](https://github.com/lestrrat-go/jwx/pull/2256)
- build(deps): bump actions/stale from 10.3.0 to 10.4.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2255](https://github.com/lestrrat-go/jwx/pull/2255)
- build(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2252](https://github.com/lestrrat-go/jwx/pull/2252)
- build(deps): bump actions/setup-go from 6.5.0 to 7.0.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2259](https://github.com/lestrrat-go/jwx/pull/2259)
- build(deps): bump actions/checkout from 7.0.0 to 7.0.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2262](https://github.com/lestrrat-go/jwx/pull/2262)
- \[v4] retain unparseable JWKS entries as UnsupportedKey by [@​lestrrat](https://github.com/lestrrat) in [#​2264](https://github.com/lestrrat-go/jwx/pull/2264)
- fix CodeQL autobuild for encoding/json/v2 by [@​lestrrat](https://github.com/lestrrat) in [#​2268](https://github.com/lestrrat-go/jwx/pull/2268)
- \[v4] let per-call WithRejectDuplicateKID override global by [@​lestrrat](https://github.com/lestrrat) in [#​2269](https://github.com/lestrrat-go/jwx/pull/2269)
- \[v4] test jwe rejects UnsupportedKey placeholders by [@​lestrrat](https://github.com/lestrrat) in [#​2271](https://github.com/lestrrat-go/jwx/pull/2271)
- \[v4] doc: warn that global strict JWK set parsing breaks on PQC keys by [@​lestrrat](https://github.com/lestrrat) in [#​2273](https://github.com/lestrrat-go/jwx/pull/2273)
**Full Changelog**: <https://github.com/lestrrat-go/jwx/compare/v4.1.0...v4.2.0>
### [`v4.1.0`](https://github.com/lestrrat-go/jwx/releases/tag/v4.1.0)
[Compare Source](https://github.com/lestrrat-go/jwx/compare/v4.0.2...v4.1.0)
For more detailed release notes, see [Changes](https://github.com/lestrrat-go/jwx/blob/v4.1.0/Changes).
#### What's Changed
- docs: refresh CONTRIBUTING examples link and branch example by [@​lestrrat](https://github.com/lestrrat) in [#​2156](https://github.com/lestrrat-go/jwx/pull/2156)
- autodoc updates by [@​github-actions](https://github.com/github-actions)\[bot] in [#​2157](https://github.com/lestrrat-go/jwx/pull/2157)
- add dependabot updates for develop/v4 by [@​lestrrat](https://github.com/lestrrat) in [#​2160](https://github.com/lestrrat-go/jwx/pull/2160)
- build(deps): bump actions/cache from 5.0.4 to 5.0.5 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2161](https://github.com/lestrrat-go/jwx/pull/2161)
- build(deps): bump golang.org/x/crypto from 0.49.0 to 0.51.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2162](https://github.com/lestrrat-go/jwx/pull/2162)
- build(deps): bump pozil/auto-assign-issue from 2.2.0 to 3.0.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2163](https://github.com/lestrrat-go/jwx/pull/2163)
- docs: drop dead jwt error helper references by [@​lestrrat](https://github.com/lestrrat) in [#​2164](https://github.com/lestrrat-go/jwx/pull/2164)
- add claude code plugin and supporting docs by [@​lestrrat](https://github.com/lestrrat) in [#​2165](https://github.com/lestrrat-go/jwx/pull/2165)
- tighten companion-bulk skill rules by [@​lestrrat](https://github.com/lestrrat) in [#​2166](https://github.com/lestrrat-go/jwx/pull/2166)
- docs: add claude code skill install instructions by [@​lestrrat](https://github.com/lestrrat) in [#​2167](https://github.com/lestrrat-go/jwx/pull/2167)
- docs: add DeepWiki badge to README by [@​lestrrat](https://github.com/lestrrat) in [#​2168](https://github.com/lestrrat-go/jwx/pull/2168)
- ci: make v4 fuzz workflow actually run by [@​lestrrat](https://github.com/lestrrat) in [#​2169](https://github.com/lestrrat-go/jwx/pull/2169)
- ci: rotate companion fuzz cache via per-run key by [@​lestrrat](https://github.com/lestrrat) in [#​2170](https://github.com/lestrrat-go/jwx/pull/2170)
- docs: explain fuzz template skip-list by [@​lestrrat](https://github.com/lestrrat) in [#​2171](https://github.com/lestrrat-go/jwx/pull/2171)
- build(deps): bump actions/stale from 10.2.0 to 10.3.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2175](https://github.com/lestrrat-go/jwx/pull/2175)
- build(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2181](https://github.com/lestrrat-go/jwx/pull/2181)
- build(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2182](https://github.com/lestrrat-go/jwx/pull/2182)
- build(deps): bump actions/checkout from 6.0.2 to 6.0.3 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2185](https://github.com/lestrrat-go/jwx/pull/2185)
- build(deps): bump pozil/auto-assign-issue from 3.0.0 to 4.0.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2186](https://github.com/lestrrat-go/jwx/pull/2186)
- docs: warn about anchoring RegexpWhitelist patterns by [@​lestrrat](https://github.com/lestrrat) in [#​2187](https://github.com/lestrrat-go/jwx/pull/2187)
- autodoc updates by [@​github-actions](https://github.com/github-actions)\[bot] in [#​2188](https://github.com/lestrrat-go/jwx/pull/2188)
- build(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2193](https://github.com/lestrrat-go/jwx/pull/2193)
- build(deps): bump pozil/auto-assign-issue from 4.0.0 to 4.0.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2194](https://github.com/lestrrat-go/jwx/pull/2194)
- clear pooled error slice before reuse by [@​lestrrat](https://github.com/lestrrat) in [#​2195](https://github.com/lestrrat-go/jwx/pull/2195)
- avoid full-string rune alloc in alg error by [@​lestrrat](https://github.com/lestrrat) in [#​2196](https://github.com/lestrrat-go/jwx/pull/2196)
- release json registry lock before decoder call by [@​lestrrat](https://github.com/lestrrat) in [#​2197](https://github.com/lestrrat-go/jwx/pull/2197)
- compute cbc-hmac aad bit length in uint64 by [@​lestrrat](https://github.com/lestrrat) in [#​2198](https://github.com/lestrrat-go/jwx/pull/2198)
- error on nil curve and oversized d at import by [@​lestrrat](https://github.com/lestrrat) in [#​2199](https://github.com/lestrrat-go/jwx/pull/2199)
- error on unavailable thumbprint hash by [@​lestrrat](https://github.com/lestrrat) in [#​2200](https://github.com/lestrrat-go/jwx/pull/2200)
- handle nil clock and validator in validate by [@​lestrrat](https://github.com/lestrrat) in [#​2202](https://github.com/lestrrat-go/jwx/pull/2202)
- reset private claims on token unmarshal by [@​lestrrat](https://github.com/lestrrat) in [#​2203](https://github.com/lestrrat-go/jwx/pull/2203)
- apply jwt settings only when supplied by [@​lestrrat](https://github.com/lestrrat) in [#​2204](https://github.com/lestrrat-go/jwx/pull/2204)
- validate use field at jwk parse time by [@​lestrrat](https://github.com/lestrrat) in [#​2205](https://github.com/lestrrat-go/jwx/pull/2205)
- document intentional ecdsa high-s acceptance by [@​lestrrat](https://github.com/lestrrat) in [#​2213](https://github.com/lestrrat-go/jwx/pull/2213)
- read jwe zip only from protected header by [@​lestrrat](https://github.com/lestrrat) in [#​2206](https://github.com/lestrrat-go/jwx/pull/2206)
- enforce aead wire tag and iv length on decrypt by [@​lestrrat](https://github.com/lestrrat) in [#​2207](https://github.com/lestrrat-go/jwx/pull/2207)
- require 8-octet minimum pbes2 salt by [@​lestrrat](https://github.com/lestrrat) in [#​2208](https://github.com/lestrrat-go/jwx/pull/2208)
- require empty encrypted\_key for direct cek by [@​lestrrat](https://github.com/lestrrat) in [#​2209](https://github.com/lestrrat-go/jwx/pull/2209)
- error on wrong-length [`ed25519`](https://github.com/lestrrat-go/jwx/commit/ed25519) key by [@​lestrrat](https://github.com/lestrrat) in [#​2201](https://github.com/lestrrat-go/jwx/pull/2201)
- enforce protected alg match in jws verify by [@​lestrrat](https://github.com/lestrrat) in [#​2212](https://github.com/lestrrat-go/jwx/pull/2212)
- document intentional lenient base64 in verify by [@​lestrrat](https://github.com/lestrrat) in [#​2214](https://github.com/lestrrat-go/jwx/pull/2214)
- reject detached payload when payload present by [@​lestrrat](https://github.com/lestrrat) in [#​2211](https://github.com/lestrrat-go/jwx/pull/2211)
- document jwk alg is informational, not validated by [@​lestrrat](https://github.com/lestrrat) in [#​2215](https://github.com/lestrrat-go/jwx/pull/2215)
- document symmetric key length not validated by [@​lestrrat](https://github.com/lestrrat) in [#​2216](https://github.com/lestrrat-go/jwx/pull/2216)
- document rsa private params not validated by [@​lestrrat](https://github.com/lestrrat) in [#​2217](https://github.com/lestrrat-go/jwx/pull/2217)
- note AlgorithmsForKey does not validate key length by [@​lestrrat](https://github.com/lestrrat) in [#​2222](https://github.com/lestrrat-go/jwx/pull/2222)
- document okp public key not bound to scalar by [@​lestrrat](https://github.com/lestrrat) in [#​2219](https://github.com/lestrrat-go/jwx/pull/2219)
- document Chain.Get returns aliased read-only slice by [@​lestrrat](https://github.com/lestrrat) in [#​2220](https://github.com/lestrrat-go/jwx/pull/2220)
- fix WithPedantic doc: typ is not checked by [@​lestrrat](https://github.com/lestrrat) in [#​2221](https://github.com/lestrrat-go/jwx/pull/2221)
- document ec private scalar not bound to point by [@​lestrrat](https://github.com/lestrrat) in [#​2218](https://github.com/lestrrat-go/jwx/pull/2218)
- extend direct-mode empty key guard to ml-kem by [@​lestrrat](https://github.com/lestrrat) in [#​2223](https://github.com/lestrrat-go/jwx/pull/2223)
- add bazel test target for internal/json by [@​lestrrat](https://github.com/lestrrat) in [#​2224](https://github.com/lestrrat-go/jwx/pull/2224)
- build(deps): bump actions/checkout from 6.0.3 to 7.0.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2227](https://github.com/lestrrat-go/jwx/pull/2227)
- build(deps): bump actions/cache from 5.0.5 to 6.0.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2232](https://github.com/lestrrat-go/jwx/pull/2232)
- build(deps): bump actions/setup-go from 6.4.0 to 6.5.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2233](https://github.com/lestrrat-go/jwx/pull/2233)
- fix: reject duplicate JOSE headers on fast path by [@​lestrrat](https://github.com/lestrrat) in [#​2236](https://github.com/lestrrat-go/jwx/pull/2236)
- build(deps): bump actions/cache from 6.0.0 to 6.1.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2239](https://github.com/lestrrat-go/jwx/pull/2239)
- docs: add unreleased Changes entries by [@​lestrrat](https://github.com/lestrrat) in [#​2240](https://github.com/lestrrat-go/jwx/pull/2240)
- chore: run jwkfetch in companion test sweep by [@​lestrrat](https://github.com/lestrrat) in [#​2244](https://github.com/lestrrat-go/jwx/pull/2244)
**Full Changelog**: <https://github.com/lestrrat-go/jwx/compare/v4.0.2...v4.1.0>
### [`v4.0.2`](https://github.com/lestrrat-go/jwx/releases/tag/v4.0.2)
[Compare Source](https://github.com/lestrrat-go/jwx/compare/v4.0.1...v4.0.2)
For more detailed release notes, see [Changes](https://github.com/lestrrat-go/jwx/blob/v4.0.2/Changes).
#### What's Changed
- ci: print coverage summary in GitHub Actions run summary by [@​lestrrat](https://github.com/lestrrat) in [#​2078](https://github.com/lestrrat-go/jwx/pull/2078)
- ci: also run on push to target branches by [@​lestrrat](https://github.com/lestrrat) in [#​2079](https://github.com/lestrrat-go/jwx/pull/2079)
- jws: refuse "b64" header in VerifyCompactFast by [@​lestrrat](https://github.com/lestrrat) in [#​2080](https://github.com/lestrrat-go/jwx/pull/2080)
- jws: VerifyCompactFast refusals match jws.VerifyError() class by [@​lestrrat](https://github.com/lestrrat) in [#​2082](https://github.com/lestrrat-go/jwx/pull/2082)
- jws: name loose keySet options in fan-out verify error by [@​lestrrat](https://github.com/lestrrat) in [#​2084](https://github.com/lestrrat-go/jwx/pull/2084)
- jws: honor RFC 7797 b64=false in Message.MarshalJSON by [@​lestrrat](https://github.com/lestrrat) in [#​2086](https://github.com/lestrrat-go/jwx/pull/2086)
- jws: reject literal-JSON "protected" in general-form JWS by [@​lestrrat](https://github.com/lestrrat) in [#​2088](https://github.com/lestrrat-go/jwx/pull/2088)
- jwt: ParseRequest: don't skip form body on chunked transfer by [@​lestrrat](https://github.com/lestrrat) in [#​2090](https://github.com/lestrrat-go/jwx/pull/2090)
- jwt: Settings rejects out-of-range NumericDate precision by [@​lestrrat](https://github.com/lestrrat) in [#​2092](https://github.com/lestrrat-go/jwx/pull/2092)
- jwt: pedantic mode enforces cty=JWT nested-envelope shape by [@​lestrrat](https://github.com/lestrrat) in [#​2093](https://github.com/lestrrat-go/jwx/pull/2093)
- jwt: reshape base64-corruption hint as diagnosis-first by [@​lestrrat](https://github.com/lestrrat) in [#​2095](https://github.com/lestrrat-go/jwx/pull/2095)
- jwt: defensively reject missing claims in MaxDeltaIs / MinDeltaIs by [@​lestrrat](https://github.com/lestrrat) in [#​2098](https://github.com/lestrrat-go/jwx/pull/2098)
- jwt: ParseInsecure: parse loop-local payload, not original input by [@​lestrrat](https://github.com/lestrrat) in [#​2096](https://github.com/lestrrat-go/jwx/pull/2096)
- jwt: align Validate fast/slow paths to same iat,exp,nbf check order by [@​lestrrat](https://github.com/lestrrat) in [#​2100](https://github.com/lestrrat-go/jwx/pull/2100)
- jws: Verify rejects b64=false without "b64" listed in "crit" by [@​lestrrat](https://github.com/lestrrat) in [#​2101](https://github.com/lestrrat-go/jwx/pull/2101)
- jws: Sign auto-declares "b64" in "crit" when emitting b64=false by [@​lestrrat](https://github.com/lestrrat) in [#​2103](https://github.com/lestrrat-go/jwx/pull/2103)
- jws: declare "b64" as typed bool header field by [@​lestrrat](https://github.com/lestrrat) in [#​2105](https://github.com/lestrrat-go/jwx/pull/2105)
- jws: reject general-form JWS with top-level "header" sibling of "signatures" by [@​lestrrat](https://github.com/lestrrat) in [#​2107](https://github.com/lestrrat-go/jwx/pull/2107)
- jws: typed sentinel for AlgorithmsForKey unclassifiable-key failures by [@​lestrrat](https://github.com/lestrrat) in [#​2109](https://github.com/lestrrat-go/jwx/pull/2109)
- jws: VerifyMessage observes ctx cancellation between loop iterations by [@​lestrrat](https://github.com/lestrrat) in [#​2111](https://github.com/lestrrat-go/jwx/pull/2111)
- jws: cleanup follow-ups from recent review (low-severity batch) by [@​lestrrat](https://github.com/lestrrat) in [#​2113](https://github.com/lestrrat-go/jwx/pull/2113)
- jwe/jwebb: document Register{HPKE,MLKEM,MLKEMDirect}Algorithm as privileged extension points by [@​lestrrat](https://github.com/lestrrat) in [#​2115](https://github.com/lestrrat-go/jwx/pull/2115)
- jwe: DecryptMessage observes ctx cancellation between loop iterations by [@​lestrrat](https://github.com/lestrrat) in [#​2116](https://github.com/lestrrat-go/jwx/pull/2116)
- jwe: parse and bound-check PBES2 p2c in int64 space; name the violated bound by [@​lestrrat](https://github.com/lestrrat) in [#​2118](https://github.com/lestrrat-go/jwx/pull/2118)
- jwe: WithKey validates alg-vs-key shape at option-time by [@​lestrrat](https://github.com/lestrrat) in [#​2120](https://github.com/lestrrat-go/jwx/pull/2120)
- jwe: compression cap error names "decompressed" payload, the option, and the size by [@​lestrrat](https://github.com/lestrrat) in [#​2122](https://github.com/lestrrat-go/jwx/pull/2122)
- jwe: bound joined-error count and drop redundant outer Decrypt prefix by [@​lestrrat](https://github.com/lestrrat) in [#​2124](https://github.com/lestrrat-go/jwx/pull/2124)
- jwe: keySetProvider surfaces per-key errors via errors.Join by [@​lestrrat](https://github.com/lestrrat) in [#​2126](https://github.com/lestrrat-go/jwx/pull/2126)
- jwe: add WithDisabledKeyAlgorithms global policy hook by [@​lestrrat](https://github.com/lestrrat) in [#​2128](https://github.com/lestrrat-go/jwx/pull/2128)
- jwe: document WithMaxDecompressBufferSize behavior at non-positive values by [@​lestrrat](https://github.com/lestrrat) in [#​2130](https://github.com/lestrrat-go/jwx/pull/2130)
- jwk: stop duplicating JWK fields at JWKS top level on parse by [@​lestrrat](https://github.com/lestrrat) in [#​2132](https://github.com/lestrrat-go/jwx/pull/2132)
- jwk: wrap ParseKey/ParseKeyAs errors with ParseError sentinel by [@​lestrrat](https://github.com/lestrrat) in [#​2134](https://github.com/lestrrat-go/jwx/pull/2134)
- jwk: stream the keys array with cap-before-allocate by [@​lestrrat](https://github.com/lestrrat) in [#​2136](https://github.com/lestrrat-go/jwx/pull/2136)
- jwk: probe tolerates duplicate JSON field names by [@​lestrrat](https://github.com/lestrrat) in [#​2138](https://github.com/lestrrat-go/jwx/pull/2138)
- jwk: treat nil key from custom KeyParser as continue, not success by [@​lestrrat](https://github.com/lestrrat) in [#​2139](https://github.com/lestrrat-go/jwx/pull/2139)
- jwk: fix phantom ContinueParseError refs and unmarshaler typo in docs by [@​lestrrat](https://github.com/lestrrat) in [#​2141](https://github.com/lestrrat-go/jwx/pull/2141)
- jwk: add UnknownKeyTypeError typed error by [@​lestrrat](https://github.com/lestrrat) in [#​2143](https://github.com/lestrrat-go/jwx/pull/2143)
- jwk: document AKP-specific Thumbprint canonicalization on public methods by [@​lestrrat](https://github.com/lestrrat) in [#​2144](https://github.com/lestrrat-go/jwx/pull/2144)
- docs/jwk: use jwk.WithX509(true) in PEM section prose by [@​lestrrat](https://github.com/lestrrat) in [#​2145](https://github.com/lestrrat-go/jwx/pull/2145)
- docs/jwk: document EncodePEM emit-to-PEM path by [@​lestrrat](https://github.com/lestrrat) in [#​2146](https://github.com/lestrrat-go/jwx/pull/2146)
- MIGRATION: document PublicSetOf default-reject for symmetric keys by [@​lestrrat](https://github.com/lestrrat) in [#​2147](https://github.com/lestrrat-go/jwx/pull/2147)
- jwk: clarify that any value <= 0 disables the RSA strength floor by [@​lestrrat](https://github.com/lestrrat) in [#​2148](https://github.com/lestrrat-go/jwx/pull/2148)
- jwk: move extension-authoring walkthrough from doc.go to docs/04-jwk.md by [@​lestrrat](https://github.com/lestrrat) in [#​2149](https://github.com/lestrrat-go/jwx/pull/2149)
- jwk: correct Import godoc for crypto/ecdh dispatch by [@​lestrrat](https://github.com/lestrrat) in [#​2150](https://github.com/lestrrat-go/jwx/pull/2150)
- jwk: surface Export type mismatch as KeyTypeMismatchError by [@​lestrrat](https://github.com/lestrrat) in [#​2151](https://github.com/lestrrat-go/jwx/pull/2151)
- jwk: RegisterKeyImporter takes KeyImporter, not a typed function by [@​lestrrat](https://github.com/lestrrat) in [#​2152](https://github.com/lestrrat-go/jwx/pull/2152)
- Changes: draft v4.0.2 release notes by [@​lestrrat](https://github.com/lestrrat) in [#​2154](https://github.com/lestrrat-go/jwx/pull/2154)
**Full Changelog**: <https://github.com/lestrrat-go/jwx/compare/v4.0.1...v4.0.2>
### [`v4.0.1`](https://github.com/lestrrat-go/jwx/releases/tag/v4.0.1)
[Compare Source](https://github.com/lestrrat-go/jwx/compare/v4.0.0...v4.0.1)
#### What's Changed
- docs: add jwxfilter to extension modules doc by [@​lestrrat](https://github.com/lestrrat) in [#​2041](https://github.com/lestrrat-go/jwx/pull/2041)
- autodoc updates by [@​github-actions](https://github.com/github-actions)\[bot] in [#​2042](https://github.com/lestrrat-go/jwx/pull/2042)
- docs: fix broken v3-to-v4.yaml link in Changes-v4.md by [@​lestrrat](https://github.com/lestrrat) in [#​2048](https://github.com/lestrrat-go/jwx/pull/2048)
- guard ecdsa coordinates against oversized big.Int by [@​lestrrat](https://github.com/lestrrat) in [#​2049](https://github.com/lestrrat-go/jwx/pull/2049)
- reject jwe with conflicting alg in protected vs per-recipient by [@​lestrrat](https://github.com/lestrrat) in [#​2051](https://github.com/lestrrat-go/jwx/pull/2051)
- autodoc updates by [@​github-actions](https://github.com/github-actions)\[bot] in [#​2053](https://github.com/lestrrat-go/jwx/pull/2053)
- docs: document PrivateClaims concurrency contract by [@​lestrrat](https://github.com/lestrrat) in [#​2055](https://github.com/lestrrat-go/jwx/pull/2055)
- fix AddressClaim.MarshalJSON for non-printable bytes by [@​lestrrat](https://github.com/lestrrat) in [#​2054](https://github.com/lestrrat-go/jwx/pull/2054)
- jwt: only call ParseForm when WithFormKey is supplied by [@​lestrrat](https://github.com/lestrrat) in [#​2057](https://github.com/lestrrat-go/jwx/pull/2057)
- jws: jkuProvider rejects fetched keys marked use=enc by [@​lestrrat](https://github.com/lestrrat) in [#​2059](https://github.com/lestrrat-go/jwx/pull/2059)
- jwk: refuse RegisterKeyImporter for built-in raw key types by [@​lestrrat](https://github.com/lestrrat) in [#​2061](https://github.com/lestrrat-go/jwx/pull/2061)
- jwa: unify SignatureAlgorithm/KeyEncryption/ContentEncryption into one registry by [@​lestrrat](https://github.com/lestrrat) in [#​2062](https://github.com/lestrrat-go/jwx/pull/2062)
- docs: jwkbb X509 registry is a privileged extension point by [@​lestrrat](https://github.com/lestrrat) in [#​2067](https://github.com/lestrrat-go/jwx/pull/2067)
- docs(internals): record Settings unknown-option handling as design intent by [@​lestrrat](https://github.com/lestrrat) in [#​2068](https://github.com/lestrrat-go/jwx/pull/2068)
- cmd/jwx: warn on private-key-to-tty + reject keysize<=0 for oct by [@​lestrrat](https://github.com/lestrrat) in [#​2070](https://github.com/lestrrat-go/jwx/pull/2070)
- autodoc updates by [@​github-actions](https://github.com/github-actions)\[bot] in [#​2069](https://github.com/lestrrat-go/jwx/pull/2069)
- fix jwxmigrate install path in MIGRATION.md by [@​lestrrat](https://github.com/lestrrat) in [#​2076](https://github.com/lestrrat-go/jwx/pull/2076)
**Full Changelog**: <https://github.com/lestrrat-go/jwx/compare/v4.0.0...v4.0.1>
### [`v4.0.0`](https://github.com/lestrrat-go/jwx/releases/tag/v4.0.0)
[Compare Source](https://github.com/lestrrat-go/jwx/compare/v3.3.0...v4.0.0)
# Changes
v4 has many incompatibilities with v3. To see the full list of differences between
v3 and v4, please read the [Changes-v4.md file](./Changes-v4.md). Coding Agents should read [MIGRATION.md](./MIGRATION.md)
v4.0.0 - 19 Apr 2026
- Initial v4 release. Major features:
- Lighter: Core / Companion module separation. Less dependencies in core.
- Faster: Use of generics and other optimizations make v4 2x\~3x faster than before.
- Quantum-Ready: ML-KEM and ML-DSA, HPKE (+Hybrid) are supported through companion modules.
- See Changes-v4.md for a full set of Changes since v3.
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNC4xMiIsInVwZGF0ZWRJblZlciI6IjQ0LjM5LjMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):
1 additional dependency was updated
Details:
Package
Change
golang.org/x/crypto
v0.55.0 -> v0.56.0
### ℹ️ Artifact update notice
##### File name: go.mod
In order to perform the update(s) described in the table above, Renovate ran the `go get` command, which resulted in the following additional change(s):
- 1 additional dependency was updated
Details:
| **Package** | **Change** |
| :-------------------- | :--------------------- |
| `golang.org/x/crypto` | `v0.55.0` -> `v0.56.0` |
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v3.3.0→v4.5.0Release Notes
lestrrat-go/jwx (github.com/lestrrat-go/jwx/v3)
v4.5.0Compare Source
Security fix for GHSA-4cf7-xm37-g63h.
Custom claim, header, and JWK field names are now JSON-escaped on output.
Previously a name was written between the quotes as is, so a name containing
"could close its own member and add members the application never set.For example, calling
Setwith the namex":0,"adminproduced a signedtoken containing
"admin":true. Every name now yields exactly one member,and names that need no escaping serialize exactly as before. A name that is
not valid UTF-8 now fails serialization instead of being written raw.
See the Changes file for guidance on screening caller-supplied names.
Fixed in v4.5.0 and v3.3.0. v2, v1, and v0 are unmaintained and will not
receive a fix.
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.4.0...v4.5.0
v4.4.0Compare Source
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.3.0...v4.4.0
v4.3.0Compare Source
For more detailed release notes, see Changes.
What's Changed
New Contributors
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.2.0...v4.3.0
v4.2.0Compare Source
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.1.0...v4.2.0
v4.1.0Compare Source
For more detailed release notes, see Changes.
What's Changed
ed25519key by @lestrrat in #2201Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.0.2...v4.1.0
v4.0.2Compare Source
For more detailed release notes, see Changes.
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.0.1...v4.0.2
v4.0.1Compare Source
What's Changed
Full Changelog: https://github.com/lestrrat-go/jwx/compare/v4.0.0...v4.0.1
v4.0.0Compare Source
Changes
v4 has many incompatibilities with v3. To see the full list of differences between
v3 and v4, please read the Changes-v4.md file. Coding Agents should read MIGRATION.md
v4.0.0 - 19 Apr 2026
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
23c9b9a67cto93e1990acdℹ️ Artifact update notice
File name: go.mod
In order to perform the update(s) described in the table above, Renovate ran the
go getcommand, which resulted in the following additional change(s):Details:
golang.org/x/cryptov0.55.0->v0.56.093e1990acdto5067a6f00b5067a6f00btof8aecea2c1f8aecea2c1to5f5d6ab6bb5f5d6ab6bbtod48b1898f5d48b1898f5to800b7d7d4f800b7d7d4ftoc178cef027c178cef027to5f7d89e9f65f7d89e9f6to4a2a3142c5View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.