HORIZON HASKELLDocslts/ghc-9.10.xc74966e2026-09-27Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27

Modulejose-jwt-0.10.0Haskell2010

Jose.Jwt

High-level JWT encoding and decoding.

See the Jose.Jws and Jose.Jwe modules for specific JWS and JWE examples.

Example usage with a key stored as a JWK:

Example10 expressions
import Jose.Jweimport Jose.Jwaimport Jose.Jwkimport Data.ByteStringimport Data.Aeson (decodeStrict)let jsonJwk = "{\"kty\":\"RSA\", \"kid\":\"mykey\", \"n\":\"ofgWCuLjybRlzo0tZWJjNiuSfb4p4fAkd_wWJcyQoTbji9k0l8W26mPddxHmfHQp-Vaw-4qPCJrcS2mJPMEzP1Pt0Bm4d4QlL-yRT-SFd2lZS-pCgNMsD1W_YpRPEwOWvG6b32690r2jZ47soMZo9wGzjb_7OMg0LOL-bSf63kpaSHSXndS5z5rexMdbBYUsLA9e-KXBdQOS-UTo7WTBEMa2R2CapHg665xsmtdVMTBQY4uDZlxvb3qCo5ZwKh9kG4LT6_I5IhlJH7aGhyxXFvUK-DWNmoudF8NAco9_h9iaGNj8q2ethFkMLs91kzk2PAcDTW9gb54h4FRWyuXpoQ\", \"e\":\"AQAB\", \"d\":\"Eq5xpGnNCivDflJsRQBXHx1hdR1k6Ulwe2JZD50LpXyWPEAeP88vLNO97IjlA7_GQ5sLKMgvfTeXZx9SE-7YwVol2NXOoAJe46sui395IW_GO-pWJ1O0BkTGoVEn2bKVRUCgu-GjBVaYLU6f3l9kJfFNS3E0QbVdxzubSu3Mkqzjkn439X0M_V51gfpRLI9JYanrC4D4qAdGcopV_0ZHHzQlBjudU2QvXt4ehNYTCBr6XCLQUShb1juUO1ZdiYoFaFQT5Tw8bGUl_x_jTj3ccPDVZFD9pIuhLhBOneufuBiB4cS98l2SR_RQyGWSeWjnczT0QU91p1DhOVRuOopznQ\"}" :: ByteStringlet Just jwk = decodeStrict jsonJwk :: Maybe JwkRight (Jwt jwtEncoded) <- encode [jwk] (JwsEncoding RS256) (Claims "public claims")Right jwtDecoded <- Jose.Jwt.decode [jwk] (Just (JwsEncoding RS256)) jwtEncodedjwtDecodedJws (JwsHeader {jwsAlg = RS256, jwsTyp = Nothing, jwsCty = Nothing, jwsKid = Just (KeyId "mykey")},"public claims")
  • 13 types
  • 7 values
  • Packagejose-jwt-0.10.0
  • Exports20
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourceJwt.hs
newtypenewtype Jwt
#

An encoded JWT.

Constructors

Instances4Eq, Show, FromJSON, ToJSON
  • Eq JwtDefined in jose-jwt-0.10.0 · Jose.Types
  • Show JwtDefined in jose-jwt-0.10.0 · Jose.Types
  • FromJSON JwtDefined in jose-jwt-0.10.0 · Jose.Types
  • ToJSON JwtDefined in jose-jwt-0.10.0 · Jose.Types
datadata JwsHeader
#

Header content for a JWS.

Instances6Eq, Show, Generic, FromJSON, ToJSON, Rep
datadata JweHeader
#

Header content for a JWE.

Instances6Eq, Show, Generic, FromJSON, ToJSON, Rep
datadata JwtError
#

Decoding errors.

Constructors

Instances2Eq, Show
datadata JwtClaims
#

Registered claims defined in section 4 of the JWT spec.

Instances5Show, Generic, FromJSON, ToJSON, Rep
valueencode
  1. :: MonadRandom m
  2. => [Jwk]

    The key or keys. At least one must be consistent with the chosen algorithm

  3. -> JwtEncoding

    The encoding algorithm(s) used to encode the payload

  4. -> Payload

    The payload (claims)

  5. -> m (Either JwtError Jwt)

    The encoded JWT, if successful

#

Use the supplied JWKs to create a JWT. The list of keys will be searched to locate one which is consistent with the chosen encoding algorithms.

valuedecode
  1. :: MonadRandom m
  2. => [Jwk]

    The keys to use for decoding

  3. -> Maybe JwtEncoding

    The expected encoding information

  4. -> ByteString

    The encoded JWT

  5. -> m (Either JwtError JwtContent)

    The decoded JWT payload, if successful

#

Uses the supplied keys to decode a JWT. Locates a matching key by header kid value where possible or by suitable key type for the encoding algorithm.

The algorithm(s) used can optionally be supplied for validation by setting the JwtEncoding parameter, in which case an error will be returned if they don't match. If you expect the tokens to use a particular algorithm, then you should set this parameter.

For unsecured tokens (with algorithm "none"), the expected algorithm must be set to Just (JwsEncoding None) or an error will be returned.

Convenience function to return the claims contained in a JWS. This is needed in situations such as client assertion authentication, https://tools.ietf.org/html/rfc7523, where the contents of the JWT, such as the sub claim, may be required in order to work out which key should be used to verify the token.

Obviously this should not be used by itself to decode a token since no integrity checking is done and the contents may be forged.