Sample code for 30+ languages & platforms
Tcl

Decrypt a JWE into a StringBuilder

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.DecryptSb, which decrypts a recipient of a loaded JWE and writes the plaintext into a StringBuilder.

Background. The recipient index selects which recipient's key material to use. The key for that recipient must be provided before decrypting.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set jwe [new_CkJwe]

#  Load the JWE compact serialization to be decrypted.
set jweCompact "eyJhbGciOiJBMjU2S1ciLCJlbmMiOiJBMjU2R0NNIn0.<...>.<iv>.<ciphertext>.<tag>"
set success [CkJwe_LoadJwe $jwe $jweCompact]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    exit
}

#  The 256-bit key-wrapping key (base64) for recipient index 0.  In production, obtain the key
#  from a secure source rather than hard-coding it.
set base64Key "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
set success [CkJwe_SetWrappingKey $jwe 0 $base64Key "base64"]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    exit
}

#  Decrypt recipient index 0, writing the plaintext into a StringBuilder.
set sbContent [new_CkStringBuilder]

set success [CkJwe_DecryptSb $jwe 0 "utf-8" $sbContent]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkStringBuilder $sbContent
    exit
}

puts [CkStringBuilder_getAsString $sbContent]

delete_CkJwe $jwe
delete_CkStringBuilder $sbContent