Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
authlib
/
authlib
Public
Uh oh!
There was an error while loading.
Please reload this page
.
Notifications
You must be signed in to change notification settings
Fork
569
Star
5.4k
Code
Issues
119
Pull requests
30
Discussions
Actions
Projects
Security and quality
11
Insights
Additional navigation options
Code
Issues
Pull requests
Discussions
Actions
Projects
Security and quality
Insights
All pull requests
New pull request
Search pull requests
is
:
pr
state
:
closed
is:pr state:closed
Clear filter
Search
Pull requests
Open
30
(30)
Closed
320
(320)
Author
Label
Projects
Milestones
Reviews
Assignee
Sort by
Newest
descending
More items
Comfortable display density
Compact display density
ID tokens include a null nonce claim, breaking strict OIDC clients
#930
·
by
juneja-varun
was closed
Aug 27, 2026
·
·
1
2
fix(oidc): omit claims when the value is None
#923
·
by
lepture
was merged
Aug 27, 2026
Member
·
·
1
1
fix(client): client can be flexible with jwt's header
#922
·
by
lepture
was merged
Aug 27, 2026
Member
·
·
1
2
fix(oauth1): correct protocol name in InsecureTransportError description
#919
·
by
RavSinghChandan
was merged
Aug 11, 2026
·
·
fix: Always raise_for_status when parsing response token
#917
·
by
1313e
was closed
Aug 11, 2026
·
5 of 6 tasks
·
·
3
Fix RFC7523 malformed claims handling
#916
·
by
azmeuk
was merged
Jul 30, 2026
Member
·
5 tasks done
·
·
fix(jose): ignore unrecognised kty entries in import_key_set
#915
·
by
Gooh456
was closed
Jul 29, 2026
·
·
1
1
Ignore unknown kty in import_key_set (RFC 7517 §5)
#914
·
by
RalphBragg
was closed
Jul 24, 2026
·
·
1
Declare lower bounds for dependencies
#912
·
by
azmeuk
was merged
Jul 17, 2026
Member
·
5 tasks done
·
·
fix(oauth): cast sub claim to string in JWTBearerTokenGenerator
#911
·
by
levinKaus
was merged
Jul 16, 2026
Contributor
·
5 of 6 tasks
·
·
feat(client): use httpx2 instead of httpx
#909
·
by
levinKaus
was merged
Jul 21, 2026
Contributor
·
6 tasks done
·
·
1
3
fix(oauth): save device credential with authenticated client id
#908
·
by
arpitjain099
was merged
Aug 11, 2026
Contributor
·
5 of 6 tasks
·
·
1
fix: accept falsy-but-present essential claims in _validate_essential_claims
#906
·
by
binggao1230
was closed
Aug 11, 2026
·
·
1
fix: make leeway configurable in JWTBearerTokenValidator
#903
·
by
mondi04
was merged
Jun 18, 2026
Contributor
·
4 of 6 tasks
·
·
feat: add Identity Assertion JWT Authorization Grant (ID-JAG)
#898
·
by
BinoyOza-okta
was merged
Aug 31, 2026
Contributor
·
5 of 6 tasks
·
·
17
feat: add default jti claim to sign_jwt_bearer_assertion
#897
·
by
liudonggalaxy
was merged
Jun 19, 2026
Contributor
·
5 of 6 tasks
·
·
2
fix: Catch InvalidKeyIdError in RFC 9068 JWTBearerTokenValidator
#891
·
by
liudonggalaxy
was merged
May 21, 2026
Contributor
·
4 of 6 tasks
·
·
Prefer
id_token_signed_response_alg
client metadata to guess algs
role:authorization_server
spec:oidc-core
#888
·
by
azmeuk
was merged
May 18, 2026
Member
·
6 tasks done
·
·
1
Allow non-recommended algorithms in ClientSecretJWT and PrivateKey
#887
·
by
azmeuk
was merged
May 6, 2026
Member
·
·
Fix the readme links
#886
·
by
azmeuk
was merged
May 5, 2026
Member
·
2 tasks done
·
·
1
Fix RFC7523 signing with non RSA keys
spec:rfc7523
#884
·
by
azmeuk
was merged
May 6, 2026
Member
·
5 tasks done
·
·
2
git add .
#882
·
by
ahmedwirad10-collab
was closed
May 3, 2026
·
6 tasks
·
·
Fix authlib.jose deprecation warning poping from _joserfc_helpers
#881
·
by
azmeuk
was merged
May 3, 2026
Member
·
·
1
Merge release/1.6 branch
#877
·
by
lepture
was merged
Apr 13, 2026
Member
·
·
2
Update README.md docs.authlib.org/en/latest => docs.authlib.org/en/stable
#876
·
by
guillett
was merged
Apr 1, 2026
Contributor
·
1 task done
·
·
1
Previous
1
2
3
4
5
6
7
…
13
Next
You can’t perform that action at this time.