Sample code for 30+ languages & platforms
Delphi ActiveX

Set the Optional JWS Unprotected Header

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.SetUnprotectedHeader, which sets the optional unprotected header for a signature.

Background. Unlike the protected header, the unprotected header is not covered by the signature. It is carried in the JSON serialization forms of a JWS, so producing a JWS with an unprotected header yields a JSON serialization rather than compact form.

Chilkat Delphi ActiveX Downloads

Delphi ActiveX
var
success: Integer;
jws: TChilkatJws;
header: TChilkatJsonObject;
unprotected: TChilkatJsonObject;
bIncludeBom: Integer;
base64Key: WideString;
jwsJson: WideString;

begin
success := 0;

jws := TChilkatJws.Create(Self);

//  Protected header specifying HMAC-SHA256.
header := TChilkatJsonObject.Create(Self);
header.UpdateString('alg','HS256');
success := jws.SetProtectedHeader(0,header.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(jws.LastErrorText);
    Exit;
  end;

//  Set the optional unprotected header for signature 0.  Unlike the protected header, it is not
//  covered by the signature.  It is carried in the JSON serialization forms of a JWS.
unprotected := TChilkatJsonObject.Create(Self);
unprotected.UpdateString('kid','signer-key-1');
success := jws.SetUnprotectedHeader(0,unprotected.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(jws.LastErrorText);
    Exit;
  end;

bIncludeBom := 0;
success := jws.SetPayload('This is the content to sign.','utf-8',bIncludeBom);
if (success = 0) then
  begin
    Memo1.Lines.Add(jws.LastErrorText);
    Exit;
  end;

base64Key := 'YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=';
success := jws.SetMacKey(0,base64Key,'base64');
if (success = 0) then
  begin
    Memo1.Lines.Add(jws.LastErrorText);
    Exit;
  end;

//  Because an unprotected header is present, the JWS is produced in a JSON serialization form.
jwsJson := jws.CreateJws();
if (jws.LastMethodSuccess = 0) then
  begin
    Memo1.Lines.Add(jws.LastErrorText);
    Exit;
  end;
Memo1.Lines.Add(jwsJson);