Vettero

JWT Sign

Sign a JSON web token with a secret or PEM private key.

Type

crypto.jwt.sign
Block Tool Crypto
Folderbasic/crypto
Channels

Any

Pipe

Value

Scope

Any

JWT Sign builds a compact JSON web token from Payload and a signing key. Put custom claims in Payload. Use Expires in, Audience, Issuer, and the other sign options so registered claims (exp, aud, iss, …) are set correctly — do not put expiresIn inside the payload object.

Configure

SettingDescription
PayloadObject (or JSON text) of claims (required)
Key typePassphrase (HMAC) or PEM key
SecretHMAC secret when key type is passphrase
Private keyPEM private key when key type is PEM
AlgorithmHS256 (default) through HS/RS/ES/PS 256, 384, and 512. Algorithm none is not available
Expires inLifetime such as 3600 (seconds) or 1h
Not beforeDelay before the token is valid
Audienceaud
Issueriss
Subjectsub
JWT IDjti
Key IDHeader kid
HeaderOptional extra header claims (object or JSON)

Passphrase keys work with HS algorithms. PEM keys work with RS, ES, and PS algorithms.

Handles

HandleRole
In (target)Incoming connection
Out (source)Continues after signing
ErrorCatchable failures: missing secret or private key (MISSING_VALUE), or invalid payload, header, algorithm, or key (JWT_INVALID)

Connect Branch errors to Error to split those codes.

Pipe schema

The next block reads this on the data pipe (pipe.value). The value is text (the compact token).

Use case

  • Mint a bearer token, then send it on an API request.
  • Issue a short-lived token for a partner callback.
Copyright © 2026