Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

jwt.errors

import jwt

Everything here is re-exported by jwt, so import jwt is enough and the names are called as jwt.*. Importing jwt.errors on its own works too and reaches the same definitions.

The full error hierarchy raised by the jwt module. All of them inherit from JwtError, so a caller who just wants to catch “something went wrong with this token” only needs to catch that one class.

Classes

JwtError

class jwt.JwtError < Error

Base error class for all errors raised by the jwt module. Catching this class will intercept any jwt-specific error.

Constructor

jwt.JwtError(message)

Parameters

  • message (string)

MalformedTokenError

class jwt.MalformedTokenError < JwtError

Raised when a token cannot be decoded because its structure is not valid. This includes tokens that are not three dot-separated segments or that contain malformed base64url or JSON.

Constructor

jwt.MalformedTokenError(message)

SignatureError

class jwt.SignatureError < JwtError

Raised when a token’s signature does not match its header and payload. This indicates the token has been tampered with or was signed with a different key.

Constructor

jwt.SignatureError(message)

TokenExpiredError

class jwt.TokenExpiredError < JwtError

Raised when a token’s temporal claims fail validation:

  • exp (expiry): token has expired - nbf (not before): token is not yet valid - iat (issued at): token was issued in the future

Constructor

jwt.TokenExpiredError(message)

ClaimError

class jwt.ClaimError < JwtError

Raised when a required claim is absent from the token payload, or when a registered claim (iss, aud, sub) does not match the expected value.

Constructor

jwt.ClaimError(message)

AlgorithmError

class jwt.AlgorithmError < JwtError

Raised when an algorithm specified in a token header is not supported by this module, when the caller attempts to use the none algorithm without explicitly enabling it, or when a JWKS document has no key matching a token’s kid.

Constructor

jwt.AlgorithmError(message)