Sample code for 30+ languages & platforms
PHP Extension

Validate a JWS Signature

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.Validate, which validates exactly one signature, identified by a zero-based index, using the key configured at that same index.

Background. Validate returns 1 when the signature or MAC is cryptographically valid, 0 when it is not, or a negative value on error. The verifying key must be provided before validating.

Chilkat PHP Extension Downloads

PHP Extension
<?php

include("chilkat.php");

$success = false;

$jws = new CkJws();

//  Load the JWS compact serialization.
$jwsCompact = 'eyJhbGciOiJIUzI1NiJ9.VGhpcyBpcyB0aGUgY29udGVudCB0byBzaWduLg.<signature>';
$success = $jws->LoadJws($jwsCompact);
if ($success == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

//  Provide the key for signature 0 (here an HMAC key).
$base64Key = 'YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=';
$success = $jws->SetMacKey(0,$base64Key,'base64');
if ($success == false) {
    print $jws->lastErrorText() . "\n";
    exit;
}

//  Validate the signature identified by the zero-based index, using the key configured at that index.
//  Validate returns 1 when the signature or MAC is cryptographically valid, 0 when it is not, or a
//  negative value on error.
$v = $jws->Validate(0);
if ($v < 0) {
    print $jws->lastErrorText() . "\n";
    exit;
}

if ($v != 1) {
    print 'The signature is not valid.' . "\n";
    exit;
}

print 'The signature is valid.' . "\n";

?>