Sample code for 30+ languages & platforms
Xbase++

Create JWT Using HS256, HS384, or HS512

See more JSON Web Token (JWT) Examples

Demonstrates how to create a JWT using HS256, HS384, or HS512. (HS256 is JWT's acronym for HMAC-SHA256.) When HMAC is used, the secret is a shared secret (i.e. password) that both client and server know beforehand.

This example also demonstrates how to include time constraints:

  • nbf: Not Before Time
  • exp: Expiration Time
  • iat: Issue At Time

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oJwt
LOCAL oJose
LOCAL oClaims
LOCAL nCurDateTime
LOCAL cStrJwt

nSuccess := 0

//  Demonstrates how to create an HMAC JWT using a shared secret (password).

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

oJwt := CreateObject("Chilkat.Jwt")

//  Build the JOSE header
oJose := CreateObject("Chilkat.JsonObject")
//  Use HS256.  Pass the string "HS384" or "HS512" to use a different algorithm.
nSuccess := oJose:AppendString("alg", "HS256")
nSuccess := oJose:AppendString("typ", "JWT")

//  Now build the JWT claims (also known as the payload)
oClaims := CreateObject("Chilkat.JsonObject")
nSuccess := oClaims:AppendString("iss", "http://example.org")
nSuccess := oClaims:AppendString("sub", "John")
nSuccess := oClaims:AppendString("aud", "http://example.com")

//  Set the timestamp of when the JWT was created to now.
nCurDateTime := oJwt:GenNumericDate(0)
nSuccess := oClaims:AddIntAt(-1, "iat", nCurDateTime)

//  Set the "not process before" timestamp to now.
nSuccess := oClaims:AddIntAt(-1, "nbf", nCurDateTime)

//  Set the timestamp defining an expiration time (end time) for the token
//  to be now + 1 hour (3600 seconds)
nSuccess := oClaims:AddIntAt(-1, "exp", nCurDateTime + 3600)

//  Produce the smallest possible JWT:
oJwt:AutoCompact := 1

cStrJwt := oJwt:CreateJwt(oJose:Emit(), oClaims:Emit(), "secret")

? cStrJwt

oJwt:destroy()
oJose:destroy()
oClaims:destroy()