Sample code for 30+ languages & platforms
Xbase++

Create JWT using a Certificate's Private Key

See more JSON Web Token (JWT) Examples

Demonstrates how to create a JWT using a certificate's private key.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oCert
LOCAL oJwt
LOCAL oJose
LOCAL oClaims
LOCAL nCurDateTime
LOCAL cToken

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Demonstrates how to create a JWT using an certificate's private key.

oCert := CreateObject("Chilkat.Cert")

//  Load an ECC private key from a PEM file.
nSuccess := oCert:LoadPfxFile("c:/temp/myPfx.pfx", "pfxPassword")
IF (nSuccess != 1)
    ? oCert:LastErrorText
    oCert:destroy()
    RETURN
ENDIF

oJwt := CreateObject("Chilkat.Jwt")

//  Build the JOSE header
oJose := CreateObject("Chilkat.JsonObject")
//  Note: The IsEcdsa function was added in Chilkat v10.1.0
IF (oCert:IsEcdsa() == 1)
    //  Use ES256.  Pass the string "ES384" or "ES512" to use ECC with SHA-384 or SHA-512.
    oJose:AppendString("alg", "ES256")
ELSE
    //  Probably RSA...
    //  Use RS256.  Pass the string "RS384" or "RS512" to use RSA with SHA-384 or SHA-512.
    oJose:AppendString("alg", "RS256")
ENDIF

oJose:AppendString("typ", "JWT")

//  Now build the JWT claims (also known as the payload)
oClaims := CreateObject("Chilkat.JsonObject")
oClaims:AppendString("iss", "http://example.org")
oClaims:AppendString("sub", "John")
oClaims:AppendString("aud", "http://example.com")

//  Set the timestamp of when the JWT was created to now.
nCurDateTime := oJwt:GenNumericDate(0)
oClaims:AddIntAt(-1, "iat", nCurDateTime)

//  Set the "not process before" timestamp to now.
oClaims:AddIntAt(-1, "nbf", nCurDateTime)

//  Set the timestamp defining an expiration time (end time) for the token
//  to be now + 1 hour (3600 seconds)
oClaims:AddIntAt(-1, "exp", nCurDateTime + 3600)

//  Produce the smallest possible JWT:
oJwt:AutoCompact := 1

//  Create the JWT token.
cToken := oJwt:CreateJwtCert(oJose:Emit(), oClaims:Emit(), oCert)

? cToken

//  Example output:
//  eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJodHRwOi8vZXhhbXBsZS5vcmciLCJzdWIiOiJKb2huIiwiYXVkIjoiaHR0cDovL2V4YW1wbGUuY29tIiwiaWF0IjoxNDg1NzA4NzkyLCJuYmYiOjE0ODU3MDg3OTIsImV4cCI6MTQ4NTcxMjM5Mn0.wqsuyJpxJ073ox-lOiLFqG1lQocXe4hGf2XGZJRrO3qn0UusxI_bu3Gzky8gBsH4sA4u9TWZn5M-1wYMMIJk6Q

oCert:destroy()
oJwt:destroy()
oJose:destroy()
oClaims:destroy()