Release Notes: goauth v0.25.0¶
Release Date: 2026-09-26
Overview¶
This release adds a providers package for "Sign in with Google / GitHub"
login flows. It exchanges an OAuth 2.0 authorization code and returns one
normalized OAuthUser, regardless of provider. It also adds a jwt_parse
CLI for inspecting tokens, runnable Google examples, and routine dependency
updates. There are no breaking changes.
Highlights¶
- New
providerspackage: authorization-code exchange to a normalizedOAuthUserfor Google and GitHub
New Features¶
providers Package¶
import "github.com/grokify/goauth/providers"
// In your OAuth callback handler:
user, err := providers.FetchGitHubUser(ctx, githubConfig, r.URL.Query().Get("code"))
if err != nil {
return err
}
fmt.Println(user.Provider, user.ProviderID, user.Email, user.Name)
FetchGoogleUser/FetchGitHubUserexchange the code and return anOAuthUserwith the provider user ID, email, name, avatar, and the access and refresh tokens.- GitHub private emails: when the profile email is private, the primary
verified address is fetched from
/user/emails(requires theuser:emailscope).PrimaryVerifiedEmailexposes that selection, andErrNoVerifiedEmailreports users with no verified address. A missing display name falls back to the GitHub login. FetchGoogleUserWithToken/FetchGitHubUserWithTokenfetch the provider-native profile with an existing access token, using a client bounded byDefaultTimeout.- Error reporting: non-200 responses include the status code and a bounded (4 KB) excerpt of the response body.
See the Sign in with Google or GitHub guide.
cmd/jwt_parse¶
Print a JWT's claims as JSON without verifying its signature, which is useful when debugging tokens:
Google examples¶
google/cmd/oauth2web (OAuth 2.0 web flow) and google/cmd/serviceaccount
(GCP service account) load credentials from a credentials set file and fetch
the signed-in user's Google profile:
They print only token metadata (type and time to expiry) and the profile, never the credentials or tokens.
Documentation¶
- New Sign in with Google or GitHub guide.
- The README CLI section now documents
cmd/goauthwith its actual flags (--creds,--account,--url, ...). The separategoapitool it previously described was never part of the repository;goauthmakes the authenticated request itself.
Dependencies¶
google.golang.org/api0.293.0 → 0.299.0golang.org/x/oauth20.36.0 → 0.37.0golang.org/x/net0.58.0 → 0.59.0github.com/grokify/mogo0.74.7 → 0.74.9github.com/grokify/gocharts/v22.27.0 → 2.27.1