$npx skillfedfor your agent

python-jose

JOSE implementation in Python

Worth itPyPI UtilitiesReleased May 202545.9M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — python_jose-3.5.0-py2.py3-none-any.whl
v3.5.0 · released 2025-05-28 · Python >=3.9 · 3 runtime deps: ecdsa, rsa, pyasn1

Yes. python-jose is actively maintained, widely used, carries no known vulnerabilities, and is licensed permissively under MIT. It is the right choice if you need JOSE/JWT support and want flexibility in cryptographic backends.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python >=3.9.
  • The native-python backend cannot process certificates; select an alternative backend at install time for certificate support.
  • Low install friction with a pure-Python wheel distribution.

License · maintenance · safety

MIT (permissive) — MIT license (permissive) places no restrictions on use, modification, or distribution in commercial or proprietary projects.

last release 2025-05-28 (443 days) · last repo commit 2026-04-14 · 1,757 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 45,854,144 downloads/mo, #614 on PyPI

Verify before relying

pip install python-jose

from jose import jwt
token = jwt.encode({'key': 'value'}, 'secret', algorithm='HS256')
decoded = jwt.decode(token, 'secret', algorithms=['HS256'])
  • Whether the native-python backend's inability to process certificates affects your application's use cases.
  • Performance characteristics of each backend (cryptography, pycryptodome, native-python) for your workload.
  • Which backend is recommended for your specific security and dependency requirements.
Same gist for agents: .md · .json

What it is and what it does

python-jose is a production-stable implementation of the JOSE (JavaScript Object Signing and Encryption) standards in Python, providing support for JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), and JSON Web Algorithms (JWA). It allows you to cryptographically sign and encrypt JSON payloads—most commonly JSON Web Tokens (JWTs)—using a variety of algorithms, and to verify and decrypt them on the receiving end.

The package ships with three interchangeable cryptographic backends: a recommended pyca/cryptography backend, a pycryptodome backend, and a native-python backend using rsa and ecdsa. The native-python backend is always installed but can be replaced by selecting a different backend at install time. Most applications use only a small subset of the available algorithms, so you can choose the backend that best fits your security and dependency requirements.

Use it for

  • Encode and decode JWTs for stateless authentication in web APIs and microservices.
  • Sign JSON payloads to prove authenticity and integrity in inter-service communication.
  • Encrypt sensitive JSON data before transmission or storage.
  • Verify signed tokens from external OAuth2 or OpenID Connect providers.
  • Build token-based session management without server-side state.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

python-jose is actively maintained, widely used, carries no known vulnerabilities, and is licensed permissively under MIT. It is the right choice if you need JOSE/JWT support and want flexibility in cryptographic backends.

Install

python-jose on PyPI

Before you install

Low install friction with a pure-Python wheel distribution. Actively maintained with recent commits and production-stable status. Supports modern Python versions including PyPy.

Requires Python >=3.9. The native-python backend cannot process certificates; select an alternative backend at install time for certificate support.

License in practice

MIT license (permissive) places no restrictions on use, modification, or distribution in commercial or proprietary projects.

Quickstart

pip install python-jose

from jose import jwt
token = jwt.encode({'key': 'value'}, 'secret', algorithm='HS256')
decoded = jwt.decode(token, 'secret', algorithms=['HS256'])

Verify before relying

  • Whether the native-python backend's inability to process certificates affects your application's use cases.
  • Performance characteristics of each backend (cryptography, pycryptodome, native-python) for your workload.
  • Which backend is recommended for your specific security and dependency requirements.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
3 packages
ecdsarsapyasn1
MaintenanceActively maintained 443 days since the last release
Last repo commit
First released
Downloads45,854,144 / month, #614 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: PyPyTopic :: Utilities

Evidence: python_jose-3.5.0-py2.py3-none-any.whl

Tags

Capabilities
JWT signing and verificationJSON Web Token libraryJOSE implementationJWS JWE JWK supportcryptographic token handlingJSON Web Signature encryption
Topics
jwtcryptographyauthentication
PyPI keywords
josejwsjwejwtjsonwebtokensecuritysigning

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “JSON Web Token library”

  • python-joseImplements JOSE (JSON Object Signing and Encryption) standards to…
  • jwskateImplements the JOSE family of IETF standards (JWS, JWK, JWA, JWT,…
  • pyjwkestImplements JWT, JWS, JWE, and JWK standards for signing, encrypting,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also jose · josepy · joserfc · jwskate · pyjwkest · jwt · PyJWT · python-jwt · myjwt · rsa