JWT Sign
Sign a JSON web token with a secret or PEM private key.
Type
crypto.jwt.signFolder
basic/cryptoChannels
Any
Pipe
Value
Scope
Any
JWT Sign builds a compact JSON web token from Payload and a signing key. Put custom claims in Payload. Use Expires in, Audience, Issuer, and the other sign options so registered claims (exp, aud, iss, …) are set correctly — do not put expiresIn inside the payload object.
Configure
| Setting | Description |
|---|---|
| Payload | Object (or JSON text) of claims (required) |
| Key type | Passphrase (HMAC) or PEM key |
| Secret | HMAC secret when key type is passphrase |
| Private key | PEM private key when key type is PEM |
| Algorithm | HS256 (default) through HS/RS/ES/PS 256, 384, and 512. Algorithm none is not available |
| Expires in | Lifetime such as 3600 (seconds) or 1h |
| Not before | Delay before the token is valid |
| Audience | aud |
| Issuer | iss |
| Subject | sub |
| JWT ID | jti |
| Key ID | Header kid |
| Header | Optional extra header claims (object or JSON) |
Passphrase keys work with HS algorithms. PEM keys work with RS, ES, and PS algorithms.
Handles
| Handle | Role |
|---|---|
| In (target) | Incoming connection |
| Out (source) | Continues after signing |
| Error | Catchable failures: missing secret or private key (MISSING_VALUE), or invalid payload, header, algorithm, or key (JWT_INVALID) |
Connect Branch errors to Error to split those codes.
Pipe schema
The next block reads this on the data pipe (pipe.value). The value is text (the compact token).
Use case
- Mint a bearer token, then send it on an API request.
- Issue a short-lived token for a partner callback.