Standard library
nox.jwt
JSON Web Tokens signed with HMAC-SHA-256 (HS256).
Text
import nox.jwt
from nox.jwt import JwtErrorCapability: none registered (pure Nox over nox.crypto, nox.base64 and nox.json); not on the freestanding allow-list.
Functions#
| Function | Description |
|---|---|
sign(payload_json, secret) |
returns header.payload.signature for the JSON text payload_json, signed with secret |
verify(token, secret) |
checks the signature (in constant time) and returns the payload JSON text; raises JwtError for a malformed token, a wrong algorithm or a bad signature |
The token is three Base64url parts separated by dots. verify does not interpret claims: it does not check exp, nbf or aud — parse the returned payload with
nox.json and enforce them yourself.
Nox
import nox.jwt
from nox.jwt import JwtError
tok: str = nox.jwt.sign("{\"sub\":\"ada\"}", "secret")
print(tok.count("."), nox.jwt.verify(tok, "secret"))
try:
nox.jwt.verify(tok, "wrong-secret")
except JwtError as e:
print("rejected")Output
2 {"sub":"ada"}
rejectedNotes#
- Only
HS256is implemented; tokens that declare another algorithm (includingnone) are rejected. - Use a secret of at least 32 random bytes (
nox.crypto.secure_random_hex(32)) and keep it out of source control.