jsonwebtoken
v10.3.0 StableCreate and decode JWTs in a strongly typed way.
Quick Verdict
- โActively maintained (updated 59d ago)
- โStable API (10.x for 10+ years)
- โMassive adoption (13.9K crates depend on it)
- !Heavy dependency tree (24 direct deps)
- โPermissive license (MIT)
Security
Deep Insights
10.3M downloads in the last 30 days (344.3K/day), up 30% from the previous period.
13.9K crates depend on jsonwebtoken โ it's part of the Rust ecosystem's core infrastructure. Removing it from your dependency tree would be extremely difficult.
jsonwebtoken has only 1 owner despite 13.9K dependents. This is a bus-factor concern โ consider the implications for long-term support.
The API has been stable (1.x) for over 10 years with 56 releases. This level of maturity means you can depend on it without worrying about breaking changes.
24 direct dependencies. Consider the impact on compile times and supply chain complexity.
Notable dependents include google-cloud-auth, octocrab, alloy-transport-http, ethers-providers, rmcp. When high-quality crates choose jsonwebtoken, it's a strong quality signal.
Health Breakdown
Recency, release consistency, active ratio
Yanked ratio, deps, size, maturity, features
Reverse deps, ownership, ecosystem
Downloads, momentum, growth trend
Docs, repo, license, metadata
Download Trend
Top Dependents
Most downloaded crates that depend on jsonwebtoken
Version Adoption
Release Timeline
Feature Flags
default =["use_pem"]