jwt.codec
import jwt
Everything here is re-exported by
jwt, soimport jwtis enough and the names are called asjwt.*. Importingjwt.codecon its own works too and reaches the same definitions.
Algorithm identifiers and the low-level encoding helpers core.zu
builds encode()/verify() out of: base64url, HMAC dispatch, a
constant-time comparison, and the DER <-> raw-R‖S conversion ECDSA
signatures need to become JOSE-shaped.
Constants
HS256
jwt.HS256 = 'HS256'
HMAC-SHA256 signing algorithm identifier.
HS384
jwt.HS384 = 'HS384'
HMAC-SHA384 signing algorithm identifier.
HS512
jwt.HS512 = 'HS512'
HMAC-SHA512 signing algorithm identifier.
PS256
jwt.PS256 = 'PS256'
RSA-PSS-SHA256 signing algorithm identifier.
This is deliberately PS256, not RS256: this module’s RSA backing
(crypto.rsa) is RSASSA-PSS, not RSASSA-PKCS1-v1_5, and
PS256/PS384/PS512 are the JOSE-registered names (RFC 7518 §3.5)
for exactly that scheme.
PS384
jwt.PS384 = 'PS384'
RSA-PSS-SHA384 signing algorithm identifier.
PS512
jwt.PS512 = 'PS512'
RSA-PSS-SHA512 signing algorithm identifier.
ES256
jwt.ES256 = 'ES256'
ECDSA P-256 with SHA-256 signing algorithm identifier.
ES384
jwt.ES384 = 'ES384'
ECDSA P-384 with SHA-384 signing algorithm identifier.
EDDSA
jwt.EDDSA = 'EdDSA'
Ed25519 (EdDSA, RFC 8037) signing algorithm identifier.
NONE
jwt.NONE = 'none'
Unsecured algorithm identifier. Tokens signed with this algorithm carry no signature and must never be used to protect sensitive resources. Passing this value to sign() requires setting allow_none: true in options or an error will be raised.