Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

jwt.verifier

import jwt

Everything here is re-exported by jwt, so import jwt is enough and the names are called as jwt.*. Importing jwt.verifier on its own works too and reaches the same definitions.

Verifier, a reusable configured wrapper around core.verify().

Classes

Verifier

class jwt.Verifier

A reusable token verifier that holds a fixed secret and set of options.

Using a Verifier instance is the recommended approach for applications that verify many tokens with the same configuration, as it avoids passing options on every call and makes the intent of the verification parameters explicit and auditable.

Example
import jwt
import http.middleware

var verifier = jwt.Verifier('my-secret', {
  algorithms: [jwt.HS256],
  issuer: 'auth.example.com',
  audience: 'api.example.com',
  clock_tolerance: 10,
})

# In a request handler:
var token = middleware.parse_bearer(req.headers['Authorization'])
var payload = verifier.verify(token)
echo payload['role']

Constructor

jwt.Verifier(secret, options)

Parameters

  • secret (string) — The secret or PEM public key used for verification.
  • options (dict) — Verification options (see verify() for reference).

Verifier.verify()

jwt.Verifier.verify(token, options) -> dict|Token

Verifies the given token string using the secret and options bound to this Verifier.

Additional options passed here are merged with the instance options, with per-call options taking precedence. This allows overriding individual parameters (such as audience) on a per-request basis without constructing a new Verifier.

Parameters

  • token (string)
  • options (dict) — Optional per-call option overrides.

Returns dict|Token

Raises MalformedTokenError

Raises AlgorithmError

Raises SignatureError

Raises TokenExpiredError

Raises ClaimError

Verifier.decode()

jwt.Verifier.decode(token) -> Token

Decodes the given token without verification. Delegates to decode().

Parameters

  • token (string)

Returns Token

Raises MalformedTokenError