Skip to content
CAI
Software that uses CAICheck a score

joken-elixir/joken

62.9

Adequate · 3 October 2026

1.9k

lines of production code

Elixir

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Joken is a JWT library for Elixir that provides token generation, signing, and validation capabilities. It supports various cryptographic algorithms including HMAC, RSA, and EdDSA, and allows users to define custom claims and lifecycle hooks for flexible token handling. The system includes utilities for inspecting token headers and claims without validation, as well as enforcing required claims during verification.

Features

Add HMAC and RSA benchmark scripts for Joken

New benchmark scripts have been added to the benchmarks directory to measure the performance of Joken's token generation and verification. The suite includes benchmarks for HMAC algorithms (HS256, HS384, HS512) using Joken's native signers, RSA algorithms (RS256, RS384, RS512) using both Joken's native signers and the PEM RS signer, and a comparison against the JOSE library for HMAC signing. These scripts use Benchee to run 5-second benchmarks for generating/signing and verifying/validating tokens with standard claims.

benchmarks · high confidence

Add RequiredClaims hook to enforce claim presence in tokens

A new \Joken.Hooks.RequiredClaims\ hook is introduced, allowing users to configure their token definitions to demand the presence of specific claims. When added to a token configuration (e.g., \add\_hook Joken.Hooks.RequiredClaims, \[:claim1, :claim2\]\), it validates that the specified claims exist in the token payload during the validation phase. If any required claims are missing, the token validation fails with an error indicating the specific missing claims, ensuring stricter compliance with token structure requirements.

lib/joken/hooks · high confidence

Initial release of Joken 2.7.0

This entry marks the initial commit and release of the Joken JWT library (version 2.7.0). It introduces the core library structure, including the formatter configuration, Apache 2.0 license, and comprehensive documentation with usage guides. The release raises the minimum supported versions to Elixir 1.16 and OTP 26, adds a \Signer.create\ function that accepts a JOSE.JWK, and fixes the \Joken.peek/2\ function to correctly flag invalid tokens.

(repo-wide) · high confidence

New token inspection and expansion utilities

Joken now provides \peek\_header/1\ and \peek\_claims/1\ functions to decode the header or claim set of a JWT without performing signature validation, which is useful for determining the signing algorithm or inspecting untrusted tokens. Additionally, the \expand/1\ function has been added to split a signed token into its three constituent parts (protected header, payload, and signature) for low-level access.

lib · high confidence

Behavioural changes

Joken v2.0 introduces a new configuration API with dynamic claims and lifecycle hooks

This release replaces the previous API with a new module-based configuration approach using \Joken.Config\ and \Joken.Hooks\. Users can now define token configurations by using \Joken.Config\ in their modules, which provides fluent functions like \add\_claim/4\ to register dynamic claims as \Joken.Claim\ structs containing separate generation and validation functions. The library now supports lifecycle hooks (\before\_generate\, \after\_sign\, etc.) that allow intercepting and modifying token operations. Additionally, the new \Joken.Signer\ module supports EdDSA algorithms (Ed25519, Ed448) and allows creating signers from PEM keys with passphrases or JOSE JWK structs, while enforcing binary keys for HMAC algorithms.

lib/joken · high confidence

Migrate to Elixir 1.9+ config system and add Credo linting

The application configuration has been updated to use the modern \import Config\ and \config\_env()\ API, replacing the deprecated \use Mix.Config\ and \Mix.env()\ calls. This change also introduces environment-specific configuration files (\dev.exs\, \prod.exs\, \test.exs\) and a new \config/.credo.exs\ file to enforce code style and quality checks via Credo. For users, this ensures compatibility with newer Elixir versions and provides a standardized linting setup, while the test environment now includes pre-configured RSA and EC keys for signing operations.

config · high confidence

Test coverage

Added comprehensive test coverage for Joken's core modules; Added tests for the RequiredClaims hook.

Dependencies

Joken 2.7.0: Major dependency overhaul and Elixir 1.16 support

This release updates the Joken library to version 2.7.0 and raises the minimum required Elixir version to 1.16. The dependency tree has been significantly modernized: the JSON handling has shifted from the legacy \jsex\/\jsx\/\jazz\ stack to \jose\ (for cryptographic operations) and \jason\ (for JSON encoding/decoding in dev/test environments). Development tooling has also been updated, including \ex\_doc\ to 0.40.3, \credo\ to 1.7, \dialyxir\ to 1.4, and \excoveralls\ to 0.18, while test dependencies like \stream\_data\ and \junit\_formatter\ have been bumped to their latest compatible versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 61 → 63 (+2.1)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 100 → 100 (+0.0)
  • Architecture 80 → 85 (+4.8)
  • Maturity 43 → 43 (+0.0)
  • Readiness 79 → 80 (+1.6)
  • Security 71 → 77 (+5.8)

Resolved (10)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Off-boarding risk: anonymized user #1
  • Secret: jwt (benchmarks/hs_benchmark.exs)
  • Secret: jwt (benchmarks/hs_benchmark.exs)
  • Secret: jwt (benchmarks/hs_benchmark.exs)
  • Secret: jwt (lib/joken.ex)
  • Secret: jwt (lib/joken.ex)
  • Secret: jwt (lib/joken/signer.ex)
  • Secret: jwt (lib/joken/signer.ex)

New (2)

  • Off-boarding risk: anonymized user #1
  • Secret: jwt (lib/joken/signer.ex)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

joken-elixir/joken was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b0654ecfef94b22e6d39c74c110b4ad240885c24 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-8fe32cd45d00.