Sample code for 30+ languages & platforms
Zig

Validate a JWS Signature

See more JSON Web Signatures (JWS) Examples

Demonstrates Jws.Validate, which validates exactly one signature, identified by a zero-based index, using the key configured at that same index.

Background. Validate returns 1 when the signature or MAC is cryptographically valid, 0 when it is not, or a negative value on error. The verifying key must be provided before validating.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    const jws = try chilkat.Jws.init();
    defer jws.deinit();

    // Load the JWS compact serialization.
    const jws_compact = "eyJhbGciOiJIUzI1NiJ9.VGhpcyBpcyB0aGUgY29udGVudCB0byBzaWduLg.<signature>";
    jws.loadJws(jws_compact) catch {
        std.debug.print("{s}\n", .{try jws.getLastErrorText(alloc)});
        return;
    };

    // Provide the key for signature 0 (here an HMAC key).
    const base64_key = "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXowMTIzNDU=";
    jws.setMacKey(0, base64_key, "base64") catch {
        std.debug.print("{s}\n", .{try jws.getLastErrorText(alloc)});
        return;
    };

    // Validate the signature identified by the zero-based index, using the key configured at that index.
    // Validate returns 1 when the signature or MAC is cryptographically valid, 0 when it is not, or a
    // negative value on error.
    const v = jws.validate(0);
    if (v < 0) {
        std.debug.print("{s}\n", .{try jws.getLastErrorText(alloc)});
        return;
    }

    if (v != 1) {
        std.debug.print("{s}\n", .{try jws.getLastErrorText(alloc)});
        std.debug.print("The signature is not valid.\n", .{});
        return;
    }

    std.debug.print("The signature is valid.\n", .{});
}