Sample code for 30+ languages & platforms
Xbase++

Validate a JWS Signature

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.Validate, which validates exactly one signature, identified by a zero-based index, using the key configured at that same index.

Background. Validate returns 1 when the signature or MAC is cryptographically valid, 0 when it is not, or a negative value on error. The verifying key must be provided before validating.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oJws
LOCAL cJwsCompact
LOCAL cBase64Key
LOCAL v

nSuccess := 0

oJws := CreateObject("Chilkat.Jws")

//  Load the JWS compact serialization.
cJwsCompact := "eyJhbGciOiJIUzI1NiJ9.VGhpcyBpcyB0aGUgY29udGVudCB0byBzaWduLg.<signature>"
nSuccess := oJws:LoadJws(cJwsCompact)
IF (nSuccess == 0)
    ? oJws:LastErrorText
    oJws:destroy()
    RETURN
ENDIF

//  Provide the key for signature 0 (here an HMAC key).
cBase64Key := "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU="
nSuccess := oJws:SetMacKey(0, cBase64Key, "base64")
IF (nSuccess == 0)
    ? oJws:LastErrorText
    oJws:destroy()
    RETURN
ENDIF

//  Validate the signature identified by the zero-based index, using the key configured at that index.
//  Validate returns 1 when the signature or MAC is cryptographically valid, 0 when it is not, or a
//  negative value on error.
v := oJws:Validate(0)
IF (v < 0)
    ? oJws:LastErrorText
    oJws:destroy()
    RETURN
ENDIF

IF (v != 1)
    ? oJws:LastErrorText
    ? "The signature is not valid."
    oJws:destroy()
    RETURN
ENDIF

? "The signature is valid."

oJws:destroy()