Sample code for 30+ languages & platforms
React Native Requires Chilkat v11.0.0+

JWS Using HMAC SHA-256

See more JSON Web Signatures (JWS) Examples

Creates a JSON Web Signatures (JWS) using HMAC SHA-256.

Chilkat React Native Downloads

React Native
import { JsonObject, Jws } from '@chilkat/react-native'

function chilkatExample() {
  // This requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // First create the JWS Protected Header
  const jwsProtHdr = new JsonObject();
  jwsProtHdr.appendString('typ', 'JWT');
  jwsProtHdr.appendString('alg', 'HS256');
  console.log(`JWS Protected Header: ${jwsProtHdr.emit()}`);

  // Output:
  // JWS Protected Header: {"typ":"JWT","alg":"HS256"}

  const jws = new Jws();

  // Set the HMAC key:
  const hmacKey = 'AyM1SysPpbyDfgZld3umj1qzKObwVMkoqQ-EstJQLr_T-1qS0gZH75aKtMN3Yj0iPS4hcgUuTwjAzZr1Z9CAow';
  let signatureIndex = 0;
  jws.setMacKey(signatureIndex, hmacKey, 'base64url');

  // Set the protected header:
  jws.setProtectedHeader(signatureIndex, jwsProtHdr);

  // Set the payload.
  const bIncludeBom = false;
  const payloadStr = 'In our village, folks say God crumbles up the old moon into stars.';
  jws.setPayload(payloadStr, 'utf-8', bIncludeBom);

  // Create the JWS
  // By default, the compact serialization is used.
  let jwsCompact: string;
  try {
    jwsCompact = jws.createJws();
  } catch {
    console.log(jws.lastErrorText);
    return;
  }

  console.log(`JWS: ${jwsCompact}`);

  // sample output:
  // JWS: eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.SW4gb3VyIHZpbGxhZ2UsIGZvbGtzIHNheSBHb2QgY3J1bWJsZXMgdXAgdGhlIG9sZCBtb29uIGludG8gc3RhcnMu.bsYsi8HJ0N6OqGI1hKQ9QQRNPxxA5qMpcHLtOvXatk8

  // Now load the JWS, validate, and recover the original text.
  const jws2 = new Jws();

  // Load the JWS.
  jws2.loadJws(jwsCompact);

  // Set the MAC key used for validation.
  signatureIndex = 0;
  jws2.setMacKey(signatureIndex, hmacKey, 'base64url');

  // Validate the 1st (and only) signature at index 0..
  const v = jws2.validate(signatureIndex);
  if (v < 0) {
    // Perhaps Chilkat was not unlocked or the trial expired..
    console.log('Method call failed for some other reason.');
    console.log(jws2.lastErrorText);
    return;
  }

  if (v === 0) {
    console.log('Invalid signature.  The MAC key was incorrect, the JWS was invalid, or both.');
    return;
  }

  // If we get here, the signature was validated..
  console.log('Signature validated.');

  // Recover the original content:
  console.log(jws2.getPayload('utf-8'));

  // Examine the protected header:

  const joseHeader = new JsonObject();
  try {
    jws2.getProtectedH(signatureIndex, joseHeader);
  } catch {
    console.log(jws2.lastErrorText);
    return;
  }

  joseHeader.emitCompact = false;

  console.log('Protected (JOSE) header:');
  console.log(joseHeader.emit());

  // Output:

  // 	Signature validated.
  // 	In our village, folks say God crumbles up the old moon into stars.
  // 	Protected (JOSE) header:
  // 	{ 
  // 	  "typ": "JWT",
  // 	  "alg": "HS256"
  // 	} 
}