Sample code for 30+ languages & platforms
PHP ActiveX

Sign a JWS with an HMAC Key

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.SetMacKey, which sets the symmetric MAC key for a signature. The key bytes are supplied in a named encoding such as hex or base64.

Background. HMAC-based JWS (for example HS256) authenticates the payload with a shared symmetric key that both signer and verifier possess.

Chilkat PHP ActiveX Downloads

PHP ActiveX
<?php

$success = 0;

$jws = new COM("Chilkat.Jws");

//  Protected header specifying HMAC-SHA256.
$header = new COM("Chilkat.JsonObject");
$header->UpdateString('alg','HS256');
$success = $jws->SetProtectedHeader(0,$header);
if ($success == 0) {
    print $jws->LastErrorText . "\n";
    exit;
}

$bIncludeBom = 0;
$success = $jws->SetPayload('This is the content to sign.','utf-8',$bIncludeBom);
if ($success == 0) {
    print $jws->LastErrorText . "\n";
    exit;
}

//  Set the symmetric MAC key for signature 0.  The key bytes are provided in the named encoding (here
//  base64).  In production, obtain the key from a secure source rather than hard-coding it.
$base64Key = 'YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=';
$success = $jws->SetMacKey(0,$base64Key,'base64');
if ($success == 0) {
    print $jws->LastErrorText . "\n";
    exit;
}

$jwsCompact = $jws->createJws();
if ($jws->LastMethodSuccess == 0) {
    print $jws->LastErrorText . "\n";
    exit;
}

print $jwsCompact . "\n";

?>