Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

jwt.jwks

import jwt

Everything here is re-exported by jwt, so import jwt is enough and the names are called as jwt.*. Importing jwt.jwks on its own works too and reaches the same definitions.

Jwks, plus verify_with_jwks(): resolving a token’s signing key from a JSON Web Key Set (RFC 7517) by its kid header, rather than a single fixed secret/key.

Functions

verify_with_jwks()

jwt.verify_with_jwks(token, jwks: instance, options) -> dict|Token

Verifies a token by resolving its signing key from a JWKS document rather than a single fixed secret.

Reads the token’s kid header parameter, resolves the matching key in jwks, converts it to a PEM, and verifies the token with it exactly as verify() would with that PEM passed directly.

Parameters

  • token (string)
  • jwks (Jwks)
  • options (?dict) — See verify() for the full reference; note that algorithms should still be set explicitly here, the same as with any other verify() call: resolving a key by kid says nothing about which algorithm is safe to trust it with.

Returns dict|Token

Raises AlgorithmError When the token has no kid, or no key in jwks matches it.

Raises MalformedTokenError

Raises SignatureError

Raises TokenExpiredError

Raises ClaimError

Raises CryptoError

Classes

Jwks

class jwt.Jwks

Parses a JSON Web Key Set document (a dict shaped like { keys: [...] }, exactly what json.decode() on a fetched JWKS document produces) and resolves individual keys by their kid.

Example
import jwt
import json

var jwks = jwt.Jwks(json.decode(fetch_jwks_document()))
var payload = jwt.verify_with_jwks(token, jwks, { issuer: 'auth.example.com' })

Constructor

jwt.Jwks(jwks: dict)

Parameters

  • jwks (dict) — A decoded JWKS document: { keys: [...] }. Keys without a kid field are ignored, since there is no way to resolve them by kid.

Jwks.find()

jwt.Jwks.find(kid: string) -> dict

Returns the raw JWK dictionary for the given kid.

Parameters

  • kid (string)

Returns dict

Raises AlgorithmError When no key with this kid is present.

Jwks.to_pem()

jwt.Jwks.to_pem(kid: string) -> string

Resolves the given kid and converts it to a PEM public key via crypto.jwk.to_pem().

Parameters

  • kid (string)

Returns string — PEM-encoded public key.

Raises AlgorithmError

Raises CryptoError