Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

jwt.token

import jwt

Everything here is re-exported by jwt, so import jwt is enough and the names are called as jwt.*. Importing jwt.token on its own works too and reaches the same definitions.

The Token class returned by decode() and verify() (when options.complete is set).

Classes

Token

class jwt.Token

Represents a decoded JWT. Instances of this class are returned by decode() and verify(). The raw header and payload dictionaries are available as properties, and individual claims are accessible directly through the index operator.

Example
import jwt

var tok = jwt.decode('ey_j...')
echo tok.header['alg']     # HS256
echo tok.payload['sub']    # '1234567890'
echo tok['sub']            # '1234567890'  (shorthand)

Fields

FieldTypeDescription
headerThe decoded header dictionary.
payloadThe decoded payload dictionary.
signatureThe raw base64url-encoded signature segment as it appeared in the original token string.
rawThe original token string from which this instance was decoded.

Constructor

jwt.Token(header, payload, signature, raw)

Parameters

  • header (dict)
  • payload (dict)
  • signature (string)
  • raw (string)

Token.set_leeway()

jwt.Token.set_leeway(seconds: number)

Token.get()

jwt.Token.get(name: string) -> any

Returns the value of the named claim from the payload, or nil if the claim is not present.

Parameters

  • name (string)

Returns any

Token.is_expired()

jwt.Token.is_expired() -> bool

Returns true when the token carries an exp claim and the current time is past that value, honoring the leeway this Token was verified with when it came from verify().

A Token produced by a bare decode() (no verification) always has zero leeway.

Returns bool