Sample code for 30+ languages & platforms
Zig

Create JWT using a Certificate's Private Key

See more JSON Web Token (JWT) Examples

Demonstrates how to create a JWT using a certificate's private key.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // Demonstrates how to create a JWT using an certificate's private key.

    const cert = try chilkat.Cert.init();
    defer cert.deinit();

    // Load an ECC private key from a PEM file.
    cert.loadPfxFile("c:/temp/myPfx.pfx", "pfxPassword") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    const jwt = try chilkat.Jwt.init();
    defer jwt.deinit();

    // Build the JOSE header
    const jose = try chilkat.JsonObject.init();
    defer jose.deinit();
    // Note: The IsEcdsa function was added in Chilkat v10.1.0
    if (cert.isEcdsa()) {
        // Use ES256.  Pass the string "ES384" or "ES512" to use ECC with SHA-384 or SHA-512.
        jose.appendString("alg", "ES256") catch {};
    } else {
        // Probably RSA...
        // Use RS256.  Pass the string "RS384" or "RS512" to use RSA with SHA-384 or SHA-512.
        jose.appendString("alg", "RS256") catch {};
    }

    jose.appendString("typ", "JWT") catch {};

    // Now build the JWT claims (also known as the payload)
    const claims = try chilkat.JsonObject.init();
    defer claims.deinit();
    claims.appendString("iss", "http://example.org") catch {};
    claims.appendString("sub", "John") catch {};
    claims.appendString("aud", "http://example.com") catch {};

    // Set the timestamp of when the JWT was created to now.
    const cur_date_time = jwt.genNumericDate(0);
    claims.addIntAt(-1, "iat", cur_date_time) catch {};

    // Set the "not process before" timestamp to now.
    claims.addIntAt(-1, "nbf", cur_date_time) catch {};

    // Set the timestamp defining an expiration time (end time) for the token
    // to be now + 1 hour (3600 seconds)
    claims.addIntAt(-1, "exp", cur_date_time + 3600) catch {};

    // Produce the smallest possible JWT:
    jwt.setAutoCompact(true);

    // Create the JWT token.
    const token = try jwt.createJwtCert(alloc, try jose.emit(alloc), try claims.emit(alloc), cert);

    std.debug.print("{s}\n", .{token});

    // Example output:
    // eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJodHRwOi8vZXhhbXBsZS5vcmciLCJzdWIiOiJKb2huIiwiYXVkIjoiaHR0cDovL2V4YW1wbGUuY29tIiwiaWF0IjoxNDg1NzA4NzkyLCJuYmYiOjE0ODU3MDg3OTIsImV4cCI6MTQ4NTcxMjM5Mn0.wqsuyJpxJ073ox-lOiLFqG1lQocXe4hGf2XGZJRrO3qn0UusxI_bu3Gzky8gBsH4sA4u9TWZn5M-1wYMMIJk6Q
}