jwt.jwks
import jwt
Everything here is re-exported by
jwt, soimport jwtis enough and the names are called asjwt.*. Importingjwt.jwkson its own works too and reaches the same definitions.
Jwks, plus verify_with_jwks(): resolving a token’s signing key from
a JSON Web Key Set (RFC 7517) by its kid header, rather than a single
fixed secret/key.
Functions
verify_with_jwks()
jwt.verify_with_jwks(token, jwks: instance, options) -> dict|Token
Verifies a token by resolving its signing key from a JWKS document rather than a single fixed secret.
Reads the token’s kid header parameter, resolves the matching key in
jwks, converts it to a PEM, and verifies the token with it exactly as
verify() would with that PEM passed directly.
Parameters
token(string)jwks(Jwks)options(?dict) — Seeverify()for the full reference; note thatalgorithmsshould still be set explicitly here, the same as with any otherverify()call: resolving a key bykidsays nothing about which algorithm is safe to trust it with.
Returns dict|Token
Raises AlgorithmError When the token has no kid, or no key in
jwks matches it.
Raises MalformedTokenError
Raises SignatureError
Raises TokenExpiredError
Raises ClaimError
Raises CryptoError
Classes
Jwks
class jwt.Jwks
Parses a JSON Web Key Set document (a dict shaped like { keys: [...] },
exactly what json.decode() on a fetched JWKS document produces) and
resolves individual keys by their kid.
Example
import jwt
import json
var jwks = jwt.Jwks(json.decode(fetch_jwks_document()))
var payload = jwt.verify_with_jwks(token, jwks, { issuer: 'auth.example.com' })
Constructor
jwt.Jwks(jwks: dict)
Parameters
jwks(dict) — A decoded JWKS document:{ keys: [...] }. Keys without akidfield are ignored, since there is no way to resolve them by kid.
Jwks.find()
jwt.Jwks.find(kid: string) -> dict
Returns the raw JWK dictionary for the given kid.
Parameters
kid(string)
Returns dict
Raises AlgorithmError When no key with this kid is present.
Jwks.to_pem()
jwt.Jwks.to_pem(kid: string) -> string
Resolves the given kid and converts it to a PEM public key via
crypto.jwk.to_pem().
Parameters
kid(string)
Returns string — PEM-encoded public key.
Raises AlgorithmError
Raises CryptoError