Sample code for 30+ languages & platforms
Tcl

Decrypt a JWE into BinData

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.DecryptBd, which decrypts a recipient of a loaded JWE and writes the plaintext bytes into a BinData.

Background. This is used when the decrypted content is binary. The recipient key must be provided before decrypting.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set jwe [new_CkJwe]

#  Load the JWE compact serialization to be decrypted.
set jweCompact "eyJhbGciOiJBMjU2S1ciLCJlbmMiOiJBMjU2R0NNIn0.<...>.<iv>.<ciphertext>.<tag>"
set success [CkJwe_LoadJwe $jwe $jweCompact]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    exit
}

#  The 256-bit key-wrapping key (base64) for recipient index 0.  In production, obtain the key
#  from a secure source rather than hard-coding it.
set base64Key "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
set success [CkJwe_SetWrappingKey $jwe 0 $base64Key "base64"]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    exit
}

#  Decrypt recipient index 0, writing the plaintext bytes into a BinData.
set bd [new_CkBinData]

set success [CkJwe_DecryptBd $jwe 0 $bd]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkBinData $bd
    exit
}

puts "Decrypted [CkBinData_get_NumBytes $bd] bytes."

delete_CkJwe $jwe
delete_CkBinData $bd