profunktor/http4s-jwt-auth
51.4
Adequate · 20 September 2026
276
lines of production code
Scala
primary language
1
measurement over time
What this system is
This system is a Scala library providing JWT authentication capabilities, specifically focusing on asymmetric key support for RSA, ECDSA, and EdDSA algorithms. It offers middleware for validating bearer tokens and managing public key configurations to enhance security by avoiding shared private keys. The project is structured as a core library with cross-building support for multiple Scala versions and utilizes modern tooling for testing and documentation.
Features
Project initialization and repository configuration
The repository has been initialized with standard project governance and development files. This includes the addition of a Code of Conduct, Contribution guidelines, and an Apache 2.0 License. Development workflows are configured via a new Nix flake for the dev shell, a Mergify configuration to automatically merge Scala Steward dependency updates, and an updated .scalafmt.conf to enforce formatting with scalafmt 3.11.5. The README has been expanded with usage examples and dependency instructions, while .gitignore has been updated to exclude IDE-specific directories.
(repo-wide) · high confidence
Support for asymmetric JWT signing and validation
The core authentication module now supports asymmetric algorithms (RSA, ECDSA, EdDSA) in addition to existing symmetric HMAC signing. Users can configure JWT validation using public keys via the new \JwtAsymmetricAuth\ type, and the \JwtAuthMiddleware\ has been updated to handle these asymmetric configurations alongside symmetric ones, allowing for more secure key management where private keys are not shared with the validation service.
core/src/main · high confidence
Removals
Removal of JWT authentication middleware and types
The JWT authentication middleware and its associated data types have been removed from the application. This change deletes the \JwtAuthMiddleware\ implementation, which previously handled bearer token validation and decoding using the \pdi.jwt\ library, as well as the \jwt.scala\ file containing the \JwtToken\, \JwtSecretKey\, and \JwtAuth\ case classes. Users relying on this specific JWT-based authentication mechanism will no longer have access to these components.
src/main · high confidence
Test coverage
Added tests for asymmetric key handling and JWT middleware behavior
Added new test suites for asymmetric key operations and JWT authentication middleware. The AsymmetricKeysSuite verifies the creation of private and public keys, successful encode/decode cycles using RSA, and proper exception handling for invalid key inputs. The JwtAuthMiddlewareSuite tests the middleware's integration with HTTP routes, covering scenarios such as valid token acceptance, rejection of missing or invalid tokens, user lookup failures, and the ability to fetch secrets via a generic effect type F\[\_\].
core/src/test · high confidence
Dependencies
Updated build toolchain and core library dependencies
The project's build infrastructure has been upgraded: SBT is updated to version 1.13.0, and core libraries including Cats (2.13.0), Cats Effect (3.7.1), fs2 (3.14.0), http4s (0.23.37), and jwt-core (11.0.4) have been bumped to their latest versions. The test framework has switched from ScalaTest to Munit (1.3.6), and the documentation tooling has moved from Tut to Mdoc (2.9.2). Additionally, sbt plugins for CI release, formatting, and binary compatibility have been updated to their latest versions.
project · high confidence
Upgrade to Scala 3.3.8 and enable cross-building
The project now supports Scala 2.12.21, 2.13.18, and 3.3.8, allowing users to build against the latest Scala 3 version. This update includes configuration for Scala 3-specific compiler options and removes compiler plugins like kind-projector that are no longer needed in Scala 3. The build structure has been reorganized into a core library module and a microsite module, with the core module now using Munit for testing instead of ScalaTest. Binary compatibility is enforced via MiMa for the 2.0.0 version.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 51.
Lenses
- Code Health 100
- Architecture 69
- Maturity 41
- Readiness 50
- Security 65
Changes since last survey
- 300 commits — 299 feature/other, 1 fixes
By area
- (repo) — 145 commits
- project/Dependencies.scala — 47 commits
- project/plugins.sbt — 41 commits
- (root) — 34 commits
- project/build.properties — 29 commits
- .github/workflows — 3 commits
- core/src — 1 commit
Notable commits
- fix: fixes #512
- change: Add 'Reformat with scalafmt 3.9.10' to .git-blame-ignore-revs
- change: Add MiMa to check for binary compatibility issues
- change: Add VersionScheme.Always for scala-xml in plugins
- change: Merge branch 'series/2.x' into update/cats-effect-3.6.0
- change: Merge pull request #460 from profunktor/MiMa
- change: Merge pull request #465 from profunktor/update/sbt-tpolecat-0.5.2
- change: Merge pull request #466 from profunktor/update/fs2-core-3.11.0
- change: Merge pull request #467 from profunktor/update/scala-library-2.12.20
- change: Merge pull request #468 from profunktor/update/http4s-server-0.23.28
- change: Merge pull request #469 from profunktor/update/munit-1.0.2
- change: Merge pull request #470 from profunktor/update/sbt-1.10.2
- change: Merge pull request #471 from profunktor/update/mdoc-2.6.1
- change: Merge pull request #472 from profunktor/update/scala-library-2.13.15
- change: Merge pull request #473 from profunktor/update/scala3-library-3.3.4
- change: Merge pull request #474 from profunktor/update/sbt-ci-release-1.7.0
- change: Merge pull request #475 from profunktor/update/sbt-ci-release-1.8.0
- change: Merge pull request #476 from profunktor/update/sbt-ci-release-1.9.0
- change: Merge pull request #477 from profunktor/update/http4s-server-0.23.29
- change: Merge pull request #478 from profunktor/update/sbt-1.10.3
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
profunktor/http4s-jwt-auth was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4b0c132344c51b2e5cc77f60e56c1f49a5b51ed4 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.