Sample code for 30+ languages & platforms
Tcl

Validate a JWS Signature

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.Validate, which validates exactly one signature, identified by a zero-based index, using the key configured at that same index.

Background. Validate returns 1 when the signature or MAC is cryptographically valid, 0 when it is not, or a negative value on error. The verifying key must be provided before validating.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

set jws [new_CkJws]

#  Load the JWS compact serialization.
set jwsCompact "eyJhbGciOiJIUzI1NiJ9.VGhpcyBpcyB0aGUgY29udGVudCB0byBzaWduLg.<signature>"
set success [CkJws_LoadJws $jws $jwsCompact]
if {$success == 0} then {
    puts [CkJws_lastErrorText $jws]
    delete_CkJws $jws
    exit
}

#  Provide the key for signature 0 (here an HMAC key).
set base64Key "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
set success [CkJws_SetMacKey $jws 0 $base64Key "base64"]
if {$success == 0} then {
    puts [CkJws_lastErrorText $jws]
    delete_CkJws $jws
    exit
}

#  Validate the signature identified by the zero-based index, using the key configured at that index.
#  Validate returns 1 when the signature or MAC is cryptographically valid, 0 when it is not, or a
#  negative value on error.
set v [CkJws_Validate $jws 0]
if {$v < 0} then {
    puts [CkJws_lastErrorText $jws]
    delete_CkJws $jws
    exit
}

if {$v != 1} then {
    puts "The signature is not valid."
    delete_CkJws $jws
    exit
}

puts "The signature is valid."

delete_CkJws $jws