Sample code for 30+ languages & platforms
PHP Extension

Set the Optional JWS Unprotected Header

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.SetUnprotectedHeader, which sets the optional unprotected header for a signature.

Background. Unlike the protected header, the unprotected header is not covered by the signature. It is carried in the JSON serialization forms of a JWS, so producing a JWS with an unprotected header yields a JSON serialization rather than compact form.

Chilkat PHP Extension Downloads

PHP Extension
<?php

include("chilkat.php");

$success = false;

$jws = new CkJws();

//  Protected header specifying HMAC-SHA256.
$header = new CkJsonObject();
$header->UpdateString('alg','HS256');
$success = $jws->SetProtectedHeader(0,$header);
if ($success == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

//  Set the optional unprotected header for signature 0.  Unlike the protected header, it is not
//  covered by the signature.  It is carried in the JSON serialization forms of a JWS.
$unprotected = new CkJsonObject();
$unprotected->UpdateString('kid','signer-key-1');
$success = $jws->SetUnprotectedHeader(0,$unprotected);
if ($success == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

$bIncludeBom = false;
$success = $jws->SetPayload('This is the content to sign.','utf-8',$bIncludeBom);
if ($success == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

$base64Key = 'YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=';
$success = $jws->SetMacKey(0,$base64Key,'base64');
if ($success == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

//  Because an unprotected header is present, the JWS is produced in a JSON serialization form.
$jwsJson = $jws->createJws();
if ($jws->get_LastMethodSuccess() == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

print $jwsJson . "\n";

?>