HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Modulejose-jwt-0.10.0Haskell2010

Jose.Jwe

JWE encrypted token support.

To create a JWE, you need to select two algorithms. One is an AES algorithm used to encrypt the content of your token (for example, A128GCM), for which a single-use key is generated internally. The second is used to encrypt this content-encryption key and can be either an RSA or AES-keywrap algorithm. You need to generate a suitable key to use with this, or load one from storage.

AES is much faster and creates shorter tokens, but both the encoder and decoder of the token need to have a copy of the key, which they must keep secret. With RSA anyone can send you a JWE if they have a copy of your public key.

In the example below, we show encoding and decoding using a 2048 bit RSA key pair (256 bytes). If using RSA, use one of the RSA_OAEP algorithms. RSA1_5 is deprecated due to known vulnerabilities.

Example7 expressions
import Jose.Jweimport Jose.Jwaimport Jose.Jwk (generateRsaKeyPair, generateSymmetricKey, KeyUse(Enc), KeyId)(kPub, kPr) <- generateRsaKeyPair 256 (KeyId "My RSA Key") Enc NothingRight (Jwt jwt) <- jwkEncode RSA_OAEP A128GCM kPub (Claims "secret claims")Right (Jwe (hdr, claims)) <- jwkDecode kPr jwtclaims"secret claims"

Using 128-bit AES keywrap is very similar, the main difference is that we generate a 128-bit symmetric key (16 bytes):

Example4 expressions
aesKey <- generateSymmetricKey 16 (KeyId "My Keywrap Key") Enc NothingRight (Jwt jwt) <- jwkEncode A128KW A128GCM aesKey (Claims "more secret claims")Right (Jwe (hdr, claims)) <- jwkDecode aesKey jwtclaims"more secret claims"
  • 4 values
  • Packagejose-jwt-0.10.0
  • Exports4
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourceJwe.hs
valuejwkEncode
  1. :: MonadRandom m
  2. => JweAlg

    Algorithm to use for key encryption

  3. -> Enc

    Content encryption algorithm

  4. -> Jwk

    The key to use to encrypt the content key

  5. -> Payload

    The token content (claims or nested JWT)

  6. -> m (Either JwtError Jwt)

    The encoded JWE if successful

#

Create a JWE using a JWK. The key and algorithms must be consistent or an error will be returned.