Skip to content

JWT Inspector v2.0.0

Latest

Choose a tag to compare

@engineering87 engineering87 released this 21 Aug 00:15
· 8 commits to main since this release

This release introduces important improvements, consistency fixes, a move to .NET 9, and a few breaking changes to the library.
The focus is on validation semantics, decoding accuracy, and developer usability.

✨ New Features

  • Case-insensitive claim and header handling.
  • Improved GetTokenSummary: safer, more readable JSON output.
  • DecodePayloadAs<T> and DecodePayloadAsJson now deserialize the raw payload instead of hydrated claims.
  • GetSigningAlgorithm returns an empty string ("") if the header is missing.
  • ValidateNotBefore(string token, TimeSpan? clockSkew = null) now supports optional clock skew.
  • Target framework updated to .NET 9.

⚠️ Breaking Changes

  • ValidateNotBefore: signature updated with optional clockSkew parameter.
  • GetCustomClaim: now returns object? instead of object.
  • ValidateLifetime: validates only temporal claims (exp, nbf), ignoring issuer, audience, and signature.
  • ValidateIssuerAndAudience: compares claims directly, without signature validation.
  • GetJwtId, GetAudience, GetIssuer: return "" (empty string) when missing instead of null.
  • Dropped support for older target frameworks; requires .NET 9.