Sample code for 30+ languages & platforms
PHP Extension

Sign a JWS with an HMAC Key

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.SetMacKey, which sets the symmetric MAC key for a signature. The key bytes are supplied in a named encoding such as hex or base64.

Background. HMAC-based JWS (for example HS256) authenticates the payload with a shared symmetric key that both signer and verifier possess.

Chilkat PHP Extension Downloads

PHP Extension
<?php

include("chilkat.php");

$success = false;

$jws = new CkJws();

//  Protected header specifying HMAC-SHA256.
$header = new CkJsonObject();
$header->UpdateString('alg','HS256');
$success = $jws->SetProtectedHeader(0,$header);
if ($success == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

$bIncludeBom = false;
$success = $jws->SetPayload('This is the content to sign.','utf-8',$bIncludeBom);
if ($success == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

//  Set the symmetric MAC key for signature 0.  The key bytes are provided in the named encoding (here
//  base64).  In production, obtain the key from a secure source rather than hard-coding it.
$base64Key = 'YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=';
$success = $jws->SetMacKey(0,$base64Key,'base64');
if ($success == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

$jwsCompact = $jws->createJws();
if ($jws->get_LastMethodSuccess() == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

print $jwsCompact . "\n";

?>