Sample code for 30+ languages & platforms
Tcl

Sign a JWS with an HMAC Key

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.SetMacKey, which sets the symmetric MAC key for a signature. The key bytes are supplied in a named encoding such as hex or base64.

Background. HMAC-based JWS (for example HS256) authenticates the payload with a shared symmetric key that both signer and verifier possess.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set jws [new_CkJws]

#  Protected header specifying HMAC-SHA256.
set header [new_CkJsonObject]

CkJsonObject_UpdateString $header "alg" "HS256"
set success [CkJws_SetProtectedHeader $jws 0 $header]
if {$success == 0} then {
    puts [CkJws_lastErrorText $jws]
    delete_CkJws $jws
    delete_CkJsonObject $header
    exit
}

set bIncludeBom 0
set success [CkJws_SetPayload $jws "This is the content to sign." "utf-8" $bIncludeBom]
if {$success == 0} then {
    puts [CkJws_lastErrorText $jws]
    delete_CkJws $jws
    delete_CkJsonObject $header
    exit
}

#  Set the symmetric MAC key for signature 0.  The key bytes are provided in the named encoding (here
#  base64).  In production, obtain the key from a secure source rather than hard-coding it.
set base64Key "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
set success [CkJws_SetMacKey $jws 0 $base64Key "base64"]
if {$success == 0} then {
    puts [CkJws_lastErrorText $jws]
    delete_CkJws $jws
    delete_CkJsonObject $header
    exit
}

set jwsCompact [CkJws_createJws $jws]
if {[CkJws_get_LastMethodSuccess $jws] == 0} then {
    puts [CkJws_lastErrorText $jws]
    delete_CkJws $jws
    delete_CkJsonObject $header
    exit
}

puts "$jwsCompact"

delete_CkJws $jws
delete_CkJsonObject $header