Come together with the global Drupal community in Rotterdam, 28 Sept – 1 Oct 2026. Sessions, contribution, connection, and Early Bird savings until 8 June.
This release addresses a known gap: prior 6.0.x versions lacked proper cache context and access‑policy support. With 6.1.0, simple_oauth now honours cache contexts and integrates with Drupal’s access‑policy mechanisms.
Drupal 11 compatibility 🚀
Drops explicit support for Drupal 9 👋
Decoupled scope (including static) definition 💪
Implemented OAuth 2.0 Security Best Current Practice 👍
For more info: #3263423: [Plan] 6.0.x Roadmap
This is the first release of the 5.2.x branch and adds PHP 8 support. There are potentially backwards-incompatible changes to error codes and JWT claim names that may affect a minority of sites; see this change record for more information.
This is a security release for the 5.0.x branch. This is the last planned release for the 5.0.x minor version of Simple OAuth.
This release corresponds with the announcement of EOL dates for the 8.x-4.x and 5.0.x branches, and the tagging of 5.1.0. The upgrade path from prior versions is well tested and supported, and all site owners are encouraged to update to 5.1.x as soon as possible. See the project page for details on EOL dates.
This is a security release for the 8.x-4.x branch. This is the last planned release for the 8.x-4.x major version of Simple OAuth.
This release corresponds with the announcement of EOL dates for the 8.x-4.x and 5.0.x branches, and the tagging of 5.1.0. The upgrade path from prior versions is well tested and supported, and all site owners are encouraged to update to 5.1.x as soon as possible. See the project page for details on EOL dates.
This is a beta release for 5.1.0, which contains important bug fixes, spec compliance and compatibility for PHP 8.
Detailed change records are in progress, but in short, this release does contain adjustments to how Simple OAuth operates, but only in so far as it moves closer to spec compliance with RFC 6749, et. al. If your clients depend on responses where Simple OAuth provided data out of line with the spec, please review this beta closely.
This is a limited-scope release to address BC-breaking behaviour in upstream libraries, specifically as they relate to RFC compliance. See #3185673: Dependency drift in jwt library breaks 5.x, which includes background and links to related issues.
Release notes are not something I enjoy writing. You can sponsor more detailed release notes. Open Source maintainers are very busy with additional professional and family obligations. Sponsoring will ensure that enterprise grade standards can be met.