Sample code for 30+ languages & platforms
CkPython

Encrypt a JWE with a Password (PBES2)

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.SetPassword, which sets the PBES2 password for a recipient. The example uses PBES2-HS256+A128KW key management with AES-128-GCM content encryption.

Background. PBES2 derives a key-wrapping key from a password using a salt and iteration count, allowing password-based JWE encryption. The password should come from a secure source.

Chilkat CkPython Downloads

CkPython
import sys
import chilkat

success = False

jwe = chilkat.CkJwe()

#  Protected header: PBES2 password-based key management with AES-128-GCM content encryption.
header = chilkat.CkJsonObject()
header.UpdateString("alg","PBES2-HS256+A128KW")
header.UpdateString("enc","A128GCM")
success = jwe.SetProtectedHeader(header)
if (success == False):
    print(jwe.lastErrorText())
    sys.exit()

#  Set the PBES2 password for recipient 0.  The password should come from a secure source rather than
#  being hard-coded.
password = "myPassword"
success = jwe.SetPassword(0,password)
if (success == False):
    print(jwe.lastErrorText())
    sys.exit()

jweCompact = jwe.encrypt("This is the secret content.","utf-8")
if (jwe.get_LastMethodSuccess() == False):
    print(jwe.lastErrorText())
    sys.exit()

print(jweCompact)