Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

jwt.codec

import jwt

Everything here is re-exported by jwt, so import jwt is enough and the names are called as jwt.*. Importing jwt.codec on its own works too and reaches the same definitions.

Algorithm identifiers and the low-level encoding helpers core.zu builds encode()/verify() out of: base64url, HMAC dispatch, a constant-time comparison, and the DER <-> raw-R‖S conversion ECDSA signatures need to become JOSE-shaped.

Constants

HS256

jwt.HS256 = 'HS256'

HMAC-SHA256 signing algorithm identifier.

HS384

jwt.HS384 = 'HS384'

HMAC-SHA384 signing algorithm identifier.

HS512

jwt.HS512 = 'HS512'

HMAC-SHA512 signing algorithm identifier.

PS256

jwt.PS256 = 'PS256'

RSA-PSS-SHA256 signing algorithm identifier.

This is deliberately PS256, not RS256: this module’s RSA backing (crypto.rsa) is RSASSA-PSS, not RSASSA-PKCS1-v1_5, and PS256/PS384/PS512 are the JOSE-registered names (RFC 7518 §3.5) for exactly that scheme.

PS384

jwt.PS384 = 'PS384'

RSA-PSS-SHA384 signing algorithm identifier.

PS512

jwt.PS512 = 'PS512'

RSA-PSS-SHA512 signing algorithm identifier.

ES256

jwt.ES256 = 'ES256'

ECDSA P-256 with SHA-256 signing algorithm identifier.

ES384

jwt.ES384 = 'ES384'

ECDSA P-384 with SHA-384 signing algorithm identifier.

EDDSA

jwt.EDDSA = 'EdDSA'

Ed25519 (EdDSA, RFC 8037) signing algorithm identifier.

NONE

jwt.NONE = 'none'

Unsecured algorithm identifier. Tokens signed with this algorithm carry no signature and must never be used to protect sensitive resources. Passing this value to sign() requires setting allow_none: true in options or an error will be raised.