jwt

package
v1.0.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 20, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

Package jwt provides an easy to use capability to work with JWT auth mechanism.

This package internally uses github.com/golang-jwt/jwt/v5 as raw implementation of the jwt specifications.

Index

Constants

View Source
const (
	JwtClaimAudience   string = "aud"
	JwtClaimIssuer     string = "iss"
	JwtClaimSubject    string = "sub"
	JwtClaimIssuedAt   string = "iat"
	JwtClaimExpiration string = "exp"
	JwtClaimNotBefore  string = "nbf"
	JwtClaimData       string = "data"
)

Standard JWT claims

Variables

SIGNING METHODS

Functions

func GetClaim

func GetClaim(token *jwt.Token, key string) (interface{}, bool)

Get claims by claim-key from provided JWT token.

func NewToken

func NewToken(feed JwtFeed, signingMethod jwt.SigningMethod) *jwt.Token

Creates new JWT token with claims and returns an instance of `jwt.Token`. Feed JwtFeed : Struct of all standard and custom claims for jwt token.

func ParseUnverifiedToken

func ParseUnverifiedToken(tokenString string) (*jwt.Token, error)

func SignECDSA

func SignECDSA(feed JwtFeed, privateKey string, kid string, signingMethod *jwt.SigningMethodECDSA) (string, error)

SignECDSA signs the token with an ECDSA private key. privateKey should be a base64-encoded PEM key.

func SignHMAC

func SignHMAC(feed JwtFeed, secret string, kid string, signingMethod *jwt.SigningMethodHMAC) (string, error)

SignHMAC signs the token with an HMAC shared secret.

func Verify

func Verify(tokenString string, cfg VerifyConfig) (bool, *jwt.Token, error)

Verifies the provided JWT token string and returns token validity status, parsed token, and error.

func VerifyECDSA

func VerifyECDSA(tokenString string, cfg VerifyConfig) (bool, *jwt.Token, error)

VerifyECDSA verifies tokens signed with ECDSA algorithms.

func VerifyHMAC

func VerifyHMAC(tokenString string, cfg VerifyConfig) (bool, *jwt.Token, error)

VerifyHMAC verifies tokens signed with HMAC algorithms.

Types

type JwtFeed

type JwtFeed struct {
	Subject      string
	Audience     string
	Issuer       string
	IssuedAt     int64
	Expiration   int64
	NotBefore    int64
	CustomClaims map[string]interface{}
}

JwtFeed represents the payload of a JWT (JSON Web Token) used for authentication and information exchange in applications. It encapsulates standard JWT claims as well as custom claims that can be provided by the application for specific use cases.

Fields:

  • Subject: Identifies the principal that is the subject of the JWT.
  • Audience: Intended recipients for which the JWT is intended.
  • Issuer: Identifies the principal that issued the JWT.
  • IssuedAt: Timestamp indicating when the JWT was issued. It is represented as seconds since Unix epoch.
  • Expiration: Timestamp indicating the time after which the JWT is no longer valid. It is represented as seconds since Unix epoch.
  • NotBefore: Timestamp indicating the time before which the JWT should not be accepted for processing. It is represented as seconds since Unix epoch.
  • CustomClaims: A map containing custom claims provided by the application. These can be used to convey additional information or attributes about the subject or other aspects related to the token's use.

type Verifier

type Verifier struct {
	Config VerifyConfig
}

Verifier adapts VerifyConfig to the core/auth Verifier interface.

func (Verifier) VerifyToken

func (v Verifier) VerifyToken(_ context.Context, token string) (interface{}, error)

VerifyToken verifies a JWT string and returns the parsed token on success.

type VerifyConfig

type VerifyConfig struct {
	ECDSAPublicKeys map[string]string // Base64-encoded PEM ECDSA public keys by kid.

	HMACSecrets map[string]string // Raw HMAC shared secrets by kid.

	ExpectedIssuer   string
	ExpectedAudience string
}

VerifyConfig defines verifier behavior and accepted key material.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL