jose
An implementation of the JOSE draft
Decision gist · record as of 2026-08-14
No. The package is unmaintained (last release 2015-11-13), targets Python 2 only, and has not received security updates in nearly a decade. For any new project, use an actively maintained JWT library. Only install if you are maintaining legacy Python 2 code that already depends on it and cannot migrate.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Python 2 only; modern Python 3 environments may not be compatible.
- Requires pycrypto or a compatible successor; installation may fail on systems without legacy crypto libraries.
- High install friction: the package is dormant (last release 2015-11-13, last commit 2024-05-30), targets Python 2 only, and has not received maintenance for nearly a decade.
License · maintenance · safety
UNKNOWN (permissive) — Licensed under BSD (permissive), so commercial and private use are permitted without restriction, but you assume all liability for security issues in unmaintained code.
last release 2015-11-13 (3927 days) · last repo commit 2024-05-30 · 100 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 244,394 downloads/mo, #8,757 on PyPI
Alternatives
Verify before relying
pip install jose==1.0.0
from jose import jwt
token = jwt.encode({'claims': 'data'}, 'secret-key')
verified = jwt.decode(token, 'secret-key')- Whether the package's cryptographic implementations remain secure against modern attack vectors given its age and lack of maintenance.
- Whether runtime dependencies are still installable and compatible with current Python versions despite Python 2-only classifier.
- Whether the backwards-incompatible changes in v1.0.0 and v0.3.0 affect your existing token ecosystem.
- What specific algorithms are supported beyond the subset mentioned in the description.
What it is and what it does
jose is a Python implementation of the JOSE (JSON Object Signing and Encryption) framework, providing tools to create and verify JWTs for secure claim transfer between parties. It supports both JWS (signed, readable tokens) and JWE (encrypted, opaque tokens) formats, along with a subset of JOSE-recommended cryptographic algorithms for authentication and authorization.
The package is dormant: its last release was in 2015-11-13, it targets Python 2 only, and it has not received active maintenance for nearly a decade. While the repository is not archived and a final commit exists from 2024-05-30, the codebase reflects its age and pre-dates modern Python versions, modern cryptographic best practices, and current JWT standards evolution. It carries no known vulnerabilities in the OSV database as of the query date, but its unmaintained status means security issues may not be discovered or patched.
Use it for
- Verify or decrypt JWTs created by older jose-based systems that predate current JWT libraries.
- Maintain legacy Python 2 codebases that already depend on jose and cannot migrate to modern alternatives.
- Prototype JOSE framework concepts in educational settings where the age of the implementation is not a concern.
- Integrate with existing systems where jose is a hard dependency and replacement is not feasible.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
The package is unmaintained (last release 2015-11-13), targets Python 2 only, and has not received security updates in nearly a decade. For any new project, use an actively maintained JWT library. Only install if you are maintaining legacy Python 2 code that already depends on it and cannot migrate.
Install
jose on PyPI
Before you install
High install friction: the package is dormant (last release 2015-11-13, last commit 2024-05-30), targets Python 2 only, and has not received maintenance for nearly a decade. Installation may require working around deprecated dependencies.
Python 2 only; modern Python 3 environments may not be compatible. Requires pycrypto or a compatible successor; installation may fail on systems without legacy crypto libraries.
License in practice
Licensed under BSD (permissive), so commercial and private use are permitted without restriction, but you assume all liability for security issues in unmaintained code.
Quickstart
pip install jose==1.0.0
from jose import jwt
token = jwt.encode({'claims': 'data'}, 'secret-key')
verified = jwt.decode(token, 'secret-key')
Verify before relying
- Whether the package's cryptographic implementations remain secure against modern attack vectors given its age and lack of maintenance.
- Whether runtime dependencies are still installable and compatible with current Python versions despite Python 2-only classifier.
- Whether the backwards-incompatible changes in v1.0.0 and v0.3.0 affect your existing token ecosystem.
- What specific algorithms are supported beyond the subset mentioned in the description.
Package facts
| License | UNKNOWN permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Dormant 3,927 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 244,394 / month, #8,757 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersIntended Audience :: Information TechnologyLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: Python :: 2 :: OnlyTopic :: SecurityTopic :: Software Development :: Libraries |
Evidence: jose-1.0.0.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “JOSE framework Python”
- joseImplements JSON Web Signature (JWS) and JSON Web Encryption (JWE) for…
- AuthlibAuthlib provides a complete implementation of OAuth 1.0, OAuth 2.0,…
- josepyImplements the JOSE (JSON Object Signing and Encryption) protocol in…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also python-jose · scitokens · jwskate · josepy · myjwt · joserfc · python-jwt · pyjwkest · jwt · Flask-JWT-Extended