Sample code for 30+ languages & platforms
Xbase++

Encrypt a JWE with a Password (PBES2)

See more JSON Web Encryption (JWE) Examples

Demonstrates Jwe.SetPassword, which sets the PBES2 password for a recipient. The example uses PBES2-HS256+A128KW key management with AES-128-GCM content encryption.

Background. PBES2 derives a key-wrapping key from a password using a salt and iteration count, allowing password-based JWE encryption. The password should come from a secure source.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oJwe
LOCAL oHeader
LOCAL cPassword
LOCAL cJweCompact

nSuccess := 0

oJwe := CreateObject("Chilkat.Jwe")

//  Protected header: PBES2 password-based key management with AES-128-GCM content encryption.
oHeader := CreateObject("Chilkat.JsonObject")
oHeader:UpdateString("alg", "PBES2-HS256+A128KW")
oHeader:UpdateString("enc", "A128GCM")
nSuccess := oJwe:SetProtectedHeader(oHeader)
IF (nSuccess == 0)
    ? oJwe:LastErrorText
    oJwe:destroy()
    oHeader:destroy()
    RETURN
ENDIF

//  Set the PBES2 password for recipient 0.  The password should come from a secure source rather than
//  being hard-coded.
cPassword := "myPassword"
nSuccess := oJwe:SetPassword(0, cPassword)
IF (nSuccess == 0)
    ? oJwe:LastErrorText
    oJwe:destroy()
    oHeader:destroy()
    RETURN
ENDIF

cJweCompact := oJwe:Encrypt("This is the secret content.", "utf-8")
IF (oJwe:LastMethodSuccess == 0)
    ? oJwe:LastErrorText
    oJwe:destroy()
    oHeader:destroy()
    RETURN
ENDIF

? cJweCompact

oJwe:destroy()
oHeader:destroy()