jwt.verifier
import jwt
Everything here is re-exported by
jwt, soimport jwtis enough and the names are called asjwt.*. Importingjwt.verifieron its own works too and reaches the same definitions.
Verifier, a reusable configured wrapper around core.verify().
Classes
Verifier
class jwt.Verifier
A reusable token verifier that holds a fixed secret and set of options.
Using a Verifier instance is the recommended approach for applications that verify many tokens with the same configuration, as it avoids passing options on every call and makes the intent of the verification parameters explicit and auditable.
Example
import jwt
import http.middleware
var verifier = jwt.Verifier('my-secret', {
algorithms: [jwt.HS256],
issuer: 'auth.example.com',
audience: 'api.example.com',
clock_tolerance: 10,
})
# In a request handler:
var token = middleware.parse_bearer(req.headers['Authorization'])
var payload = verifier.verify(token)
echo payload['role']
Constructor
jwt.Verifier(secret, options)
Parameters
secret(string) — The secret or PEM public key used for verification.options(dict) — Verification options (see verify() for reference).
Verifier.verify()
jwt.Verifier.verify(token, options) -> dict|Token
Verifies the given token string using the secret and options bound to this Verifier.
Additional options passed here are merged with the instance options, with per-call options taking precedence. This allows overriding individual parameters (such as audience) on a per-request basis without constructing a new Verifier.
Parameters
token(string)options(dict) — Optional per-call option overrides.
Returns dict|Token
Raises MalformedTokenError
Raises AlgorithmError
Raises SignatureError
Raises TokenExpiredError
Raises ClaimError
Verifier.decode()
jwt.Verifier.decode(token) -> Token
Decodes the given token without verification. Delegates to decode().
Parameters
token(string)
Returns Token
Raises MalformedTokenError