Sample code for 30+ languages & platforms
Tcl

Encrypt Content to a JWE

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.Encrypt, which encrypts a string and returns the resulting JWE. The charset argument converts the text to bytes before encryption.

Background. JWE (JSON Web Encryption) protects content with a content-encryption algorithm (the header enc value) while the content-encryption key is managed by the key-management algorithm (the header alg value). This example uses AES key wrapping with a symmetric wrapping key.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set jwe [new_CkJwe]

#  Set the JWE protected header, specifying the key-management algorithm (alg) and the content-
#  encryption algorithm (enc).
set header [new_CkJsonObject]

CkJsonObject_UpdateString $header "alg" "A256KW"
CkJsonObject_UpdateString $header "enc" "A256GCM"
set success [CkJwe_SetProtectedHeader $jwe $header]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkJsonObject $header
    exit
}

#  The 256-bit key-wrapping key (base64) for recipient index 0.  In production, obtain the key
#  from a secure source rather than hard-coding it.
set base64Key "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
set success [CkJwe_SetWrappingKey $jwe 0 $base64Key "base64"]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkJsonObject $header
    exit
}

#  Encrypt the content.  The 2nd argument is the charset used to convert the text to bytes.  The
#  returned string is the JWE (compact serialization by default).
set jweCompact [CkJwe_encrypt $jwe "This is the secret content." "utf-8"]
if {[CkJwe_get_LastMethodSuccess $jwe] == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkJsonObject $header
    exit
}

puts "$jweCompact"

delete_CkJwe $jwe
delete_CkJsonObject $header