Skip to content

Release Notes: goauth v0.25.0

Release Date: 2026-09-26

Overview

This release adds a providers package for "Sign in with Google / GitHub" login flows. It exchanges an OAuth 2.0 authorization code and returns one normalized OAuthUser, regardless of provider. It also adds a jwt_parse CLI for inspecting tokens, runnable Google examples, and routine dependency updates. There are no breaking changes.

Highlights

  • New providers package: authorization-code exchange to a normalized OAuthUser for Google and GitHub

New Features

providers Package

import "github.com/grokify/goauth/providers"

// In your OAuth callback handler:
user, err := providers.FetchGitHubUser(ctx, githubConfig, r.URL.Query().Get("code"))
if err != nil {
    return err
}
fmt.Println(user.Provider, user.ProviderID, user.Email, user.Name)
  • FetchGoogleUser / FetchGitHubUser exchange the code and return an OAuthUser with the provider user ID, email, name, avatar, and the access and refresh tokens.
  • GitHub private emails: when the profile email is private, the primary verified address is fetched from /user/emails (requires the user:email scope). PrimaryVerifiedEmail exposes that selection, and ErrNoVerifiedEmail reports users with no verified address. A missing display name falls back to the GitHub login.
  • FetchGoogleUserWithToken / FetchGitHubUserWithToken fetch the provider-native profile with an existing access token, using a client bounded by DefaultTimeout.
  • Error reporting: non-200 responses include the status code and a bounded (4 KB) excerpt of the response body.

See the Sign in with Google or GitHub guide.

cmd/jwt_parse

Print a JWT's claims as JSON without verifying its signature, which is useful when debugging tokens:

JWT_PARSE="$TOKEN" go run ./cmd/jwt_parse

Google examples

google/cmd/oauth2web (OAuth 2.0 web flow) and google/cmd/serviceaccount (GCP service account) load credentials from a credentials set file and fetch the signed-in user's Google profile:

go run ./google/cmd/oauth2web --creds credentials.json --account my-google-app

They print only token metadata (type and time to expiry) and the profile, never the credentials or tokens.

Documentation

  • New Sign in with Google or GitHub guide.
  • The README CLI section now documents cmd/goauth with its actual flags (--creds, --account, --url, ...). The separate goapi tool it previously described was never part of the repository; goauth makes the authenticated request itself.

Dependencies

  • google.golang.org/api 0.293.0 → 0.299.0
  • golang.org/x/oauth2 0.36.0 → 0.37.0
  • golang.org/x/net 0.58.0 → 0.59.0
  • github.com/grokify/mogo 0.74.7 → 0.74.9
  • github.com/grokify/gocharts/v2 2.27.0 → 2.27.1

Installation

go get github.com/grokify/goauth@v0.25.0