Sample code for 30+ languages & platforms
Delphi ActiveX

Sign a JWS with an HMAC Key

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.SetMacKey, which sets the symmetric MAC key for a signature. The key bytes are supplied in a named encoding such as hex or base64.

Background. HMAC-based JWS (for example HS256) authenticates the payload with a shared symmetric key that both signer and verifier possess.

Chilkat Delphi ActiveX Downloads

Delphi ActiveX
var
success: Integer;
jws: TChilkatJws;
header: TChilkatJsonObject;
bIncludeBom: Integer;
base64Key: WideString;
jwsCompact: WideString;

begin
success := 0;

jws := TChilkatJws.Create(Self);

//  Protected header specifying HMAC-SHA256.
header := TChilkatJsonObject.Create(Self);
header.UpdateString('alg','HS256');
success := jws.SetProtectedHeader(0,header.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(jws.LastErrorText);
    Exit;
  end;

bIncludeBom := 0;
success := jws.SetPayload('This is the content to sign.','utf-8',bIncludeBom);
if (success = 0) then
  begin
    Memo1.Lines.Add(jws.LastErrorText);
    Exit;
  end;

//  Set the symmetric MAC key for signature 0.  The key bytes are provided in the named encoding (here
//  base64).  In production, obtain the key from a secure source rather than hard-coding it.
base64Key := 'YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=';
success := jws.SetMacKey(0,base64Key,'base64');
if (success = 0) then
  begin
    Memo1.Lines.Add(jws.LastErrorText);
    Exit;
  end;

jwsCompact := jws.CreateJws();
if (jws.LastMethodSuccess = 0) then
  begin
    Memo1.Lines.Add(jws.LastErrorText);
    Exit;
  end;
Memo1.Lines.Add(jwsCompact);