Skip to content
CAI
Software that uses CAICheck a score

auth0/node-jsonwebtoken

56.7

Adequate · 1 October 2026

577

lines of production code

JavaScript

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a JSON Web Token (JWT) library for Node.js that handles token signing, verification, and decoding. It enforces strict security practices by validating key types and algorithms to prevent confusion attacks, while providing structured error handling for token expiration and validation failures. The codebase is maintained with modern tooling, including semantic versioning and comprehensive test coverage for standard and private JWT claims.

Behavioural changes

Commit message validation via commitlint

The repository now enforces commit message standards using commitlint. When a commit is created, the commit-msg hook automatically checks the message format against configured rules, ensuring consistent and semantic commit history.

.husky · high confidence

Major v9 release with breaking changes and security fixes

This release upgrades the library to version 9.0.3, updating the underlying \jws\ dependency to 4.0.1. It introduces significant breaking changes: support for Node versions 11 and below is removed, \jwt.verify()\ no longer accepts unsigned tokens by default (requiring explicit configuration), and RSA key sizes must be 2048 bits or greater. The release also addresses multiple security vulnerabilities ([CVE redacted], [CVE redacted], [CVE redacted], [CVE redacted]) related to arbitrary file writes, insecure default algorithms, and unrestricted key types. Additionally, the codebase has been refactored into separate modules (\sign.js\, \verify.js\, \decode.js\) and CI/CD infrastructure has been updated to use semantic-release with conventional commits.

(repo-wide) · high confidence

Structured error types and asymmetric key validation

The library now introduces specific error classes (JsonWebTokenError, NotBeforeError, TokenExpiredError) that provide clearer context for failures, including the expiration date or 'not before' date. Additionally, asymmetric key validation has been enhanced to strictly enforce allowed algorithms per key type (EC, RSA, RSA-PSS) and, on supported Node versions, validates specific key details like EC curves and RSA-PSS parameters to prevent algorithm confusion attacks.

lib · high confidence

Test coverage

Expanded test coverage for JWT claims and signing behavior

Added comprehensive test suites for standard JWT claims (audience, expiration, issued-at, issuer, JWT ID, not-before, subject) and private claims, including validation of option types and payload interactions. Introduced tests for asynchronous signing, buffer payloads, decoding edge cases, and cryptographic key handling (DSA, ECDSA, RSA with insecure key size checks).

test · high confidence

Dependencies

Upgrade to v9.0.3 with modernized dependencies and build tooling

The package has been updated to version 9.0.3, renaming from 'node-jsonwebtoken' to 'jsonwebtoken'. This release upgrades the core 'jws' dependency to ^4.0.1 and introduces several new dependencies including 'lodash' utility packages, 'ms' for time handling, and 'semver' for version management. The build process now enforces stricter code coverage requirements via 'nyc' and integrates 'husky' for git hooks, while the supported runtime environment is explicitly defined as Node.js \>=12 and npm \>=6.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 57 → 57 (-0.0)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 59 → 58 (-1.1)
  • Architecture 69 → 69 (+0.0)
  • Maturity 49 → 49 (+0.0)
  • Readiness 63 → 63 (+0.7)
  • Security 88 → 92 (+3.5)

Resolved (1)

  • Documentation: no licence statement (README.md)

New (7)

  • Documentation: no project overview (README.md)
  • Scanner failed to run — not a clean result
  • sign.default (cognitive 68) (sign.js)
  • sign.default (cyclomatic 55) (sign.js)
  • validateAsymmetricKey.default (cognitive 24) (lib/validateAsymmetricKey.js)
  • verify.default (cognitive 99) (verify.js)
  • verify.default (cyclomatic 78) (verify.js)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

auth0/node-jsonwebtoken was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b924272f29192e12926b5414546f7c5bfcc9579d — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.