hmacSign :: JwsAlgHMAC algorithm to use
-> ByteStringKey
-> ByteStringThe message/content
-> Either JwtError ByteStringHMAC output
Sign a message with an HMAC key.
:: a typeCtrl KGHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27
Modulejose-jwt-0.10.0Haskell2010
Internal functions for encrypting and signing / decrypting and verifying JWT content.
hmacSign :: JwsAlgHMAC algorithm to use
-> ByteStringKey
-> ByteStringThe message/content
-> Either JwtError ByteStringHMAC output
Sign a message with an HMAC key.
hmacVerify :: JwsAlgHMAC Algorithm to use
-> ByteStringKey
-> ByteStringThe message/content
-> ByteStringThe signature to check
-> BoolWhether the signature is correct
Verify the HMAC for a given message. Returns false if the MAC is incorrect or the Alg is not an HMAC.
ed25519Verify :: JwsAlg-> PublicKey-> ByteStringThe message/content
-> ByteStringThe signature to check
-> BoolWhether the signature is correct
Verify an Ed25519 signed message
ed448Verify :: JwsAlg-> PublicKey-> ByteStringThe message/content
-> ByteStringThe signature to check
-> BoolWhether the signature is correct
Verify an Ed448 signed message
rsaSign :: Maybe BlinderRSA blinder
-> JwsAlgAlgorithm to use. Must be one of RSA256, RSA384 or RSA512
-> PrivateKeyPrivate key to sign with
-> ByteStringMessage to sign
-> Either JwtError ByteStringThe signature
Sign a message using an RSA private key.
The failure condition should only occur if the algorithm is not an RSA algorithm, or the RSA key is too small, causing the padding of the signature to fail. With real-world RSA keys this shouldn't happen in practice.
rsaVerify :: JwsAlgThe signature algorithm. Used to obtain the hash function.
-> PublicKeyThe key to check the signature with
-> ByteStringThe message/content
-> ByteStringThe signature to check
-> BoolWhether the signature is correct
Verify the signature for a message using an RSA public key.
Returns false if the check fails or if the Alg value is not an RSA signature algorithm.
rsaEncrypt Encrypts a message (typically a symmetric key) using RSA.
rsaDecrypt :: ByteArray ct=> Maybe Blinder-> PrivateKeyThe decryption key
-> JweAlgThe RSA algorithm to use
-> ctThe encrypted content
-> Either JwtError ScrubbedBytesThe decrypted key
Decrypts an RSA encrypted message.
ecVerify :: JwsAlgThe signature algorithm. Used to obtain the hash function.
-> PublicKeyThe key to check the signature with
-> ByteStringThe message/content
-> ByteStringThe signature to check
-> BoolWhether the signature is correct
Verify the signature for a message using an EC public key.
Returns false if the check fails or if the Alg value is not an EC signature algorithm.
encryptPayload Encrypt a message using AES.
decryptPayload Decrypt an AES encrypted message.
generateCmkAndIV :: MonadRandom m=> EncThe encryption algorithm to be used
-> m (ScrubbedBytes, ScrubbedBytes)The key, IV
Generates the symmetric key (content management key) and IV
Used to encrypt a message.