Sample code for 30+ languages & platforms
C

Validate a JWS Signature

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.Validate, which validates exactly one signature, identified by a zero-based index, using the key configured at that same index.

Background. Validate returns 1 when the signature or MAC is cryptographically valid, 0 when it is not, or a negative value on error. The verifying key must be provided before validating.

Chilkat C Downloads

C
#include <C_CkJws.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkJws jws;
    const char *jwsCompact;
    const char *base64Key;
    int v;

    success = FALSE;

    jws = CkJws_Create();

    //  Load the JWS compact serialization.
    jwsCompact = "eyJhbGciOiJIUzI1NiJ9.VGhpcyBpcyB0aGUgY29udGVudCB0byBzaWduLg.<signature>";
    success = CkJws_LoadJws(jws,jwsCompact);
    if (success == FALSE) {
        printf("%s\n",CkJws_lastErrorText(jws));
        CkJws_Dispose(jws);
        return;
    }

    //  Provide the key for signature 0 (here an HMAC key).
    base64Key = "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=";
    success = CkJws_SetMacKey(jws,0,base64Key,"base64");
    if (success == FALSE) {
        printf("%s\n",CkJws_lastErrorText(jws));
        CkJws_Dispose(jws);
        return;
    }

    //  Validate the signature identified by the zero-based index, using the key configured at that index.
    //  Validate returns 1 when the signature or MAC is cryptographically valid, 0 when it is not, or a
    //  negative value on error.
    v = CkJws_Validate(jws,0);
    if (v < 0) {
        printf("%s\n",CkJws_lastErrorText(jws));
        CkJws_Dispose(jws);
        return;
    }

    if (v != 1) {
        printf("The signature is not valid.\n");
        CkJws_Dispose(jws);
        return;
    }

    printf("The signature is valid.\n");


    CkJws_Dispose(jws);

    }