JWT Verify
Verify a JSON web token signature and claims.
Type
crypto.jwt.verifyFolder
basic/cryptoChannels
Any
Pipe
Value
Scope
Any
JWT Verify checks the signature, pins Algorithm, and optionally checks audience, issuer, subject, JWT id, and time claims. Invalid tokens do not continue on the success outlet. JWT Decode does not replace this for authentication.
Configure
| Setting | Description |
|---|---|
| Token | Compact JWT (required) |
| Key type | Passphrase (HMAC) or PEM key |
| Secret | HMAC secret when key type is passphrase |
| Public key | PEM public key when key type is PEM |
| Algorithm | Must match how the token was signed |
| Audience | Expected aud |
| Issuer | Expected iss |
| Subject | Expected sub |
| JWT ID | Expected jti |
| Clock tolerance (seconds) | Slack for exp and nbf |
| Ignore expiration | Skip the exp check |
| Ignore not before | Skip the nbf check |
| Return additional info | Off: payload only. On: header, payload, and signature |
Handles
| Handle | Role |
|---|---|
| In (target) | Incoming connection |
| Out (source) | Continues only when the token is valid |
| Error | Catchable failures: missing token or key (MISSING_VALUE), or invalid signature, algorithm, or claims (JWT_INVALID) |
Connect Branch errors to Error to split those codes.
Pipe schema
On success the pipe is the payload object. With Return additional info it is an object with header, payload, and signature.
Catch errors with a block Error outlet or Try.
Use case
- Trust
Authorization: Bearer …on an HTTP Server handler. - Check a token you minted with JWT Sign.