Sample code for 30+ languages & platforms
Tcl

Encrypt a JWE with a Symmetric Wrapping Key

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.SetWrappingKey, which sets the symmetric key-wrapping key for a recipient. The key bytes are supplied in a named encoding such as hex or base64.

Background. AES key wrapping protects the content-encryption key with a shared symmetric key. Both parties must possess the same wrapping key.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set jwe [new_CkJwe]

#  Protected header: AES key-wrap with AES-256-GCM content encryption.
set header [new_CkJsonObject]

CkJsonObject_UpdateString $header "alg" "A256KW"
CkJsonObject_UpdateString $header "enc" "A256GCM"
set success [CkJwe_SetProtectedHeader $jwe $header]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkJsonObject $header
    exit
}

#  Set the symmetric key-wrapping key for recipient 0.  The key bytes are provided in the named
#  encoding (here base64).  In production, obtain the key from a secure source rather than hard-coding
#  it.
set base64Key "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
set success [CkJwe_SetWrappingKey $jwe 0 $base64Key "base64"]
if {$success == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkJsonObject $header
    exit
}

set jweCompact [CkJwe_encrypt $jwe "This is the secret content." "utf-8"]
if {[CkJwe_get_LastMethodSuccess $jwe] == 0} then {
    puts [CkJwe_lastErrorText $jwe]
    delete_CkJwe $jwe
    delete_CkJsonObject $header
    exit
}

puts "$jweCompact"

delete_CkJwe $jwe
delete_CkJsonObject $header