HORIZON HASKELLDocslts/ghc-9.10.xc74966e2026-09-27Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27

Modulejose-0.11Haskell2010

Crypto.JOSE.JWK

A JSON Web Key (JWK) is a JavaScript Object Notation (JSON) data structure that represents a cryptographic key. This module also defines a JSON Web Key Set (JWK Set) JSON data structure for representing a set of JWKs.

-- Generate RSA JWK and set "kid" param to
-- base64url-encoded SHA-256 thumbprint of key.
--
doGen :: IO JWK
doGen = do
  jwk <- genJWK (RSAGenParam (4096 `div` 8))
  let
    h = view thumbprint jwk :: Digest SHA256
    kid = view (re (base64url . digest) . utf8) h
  pure $ set jwkKid (Just kid) jwk
  • 54 types
  • 3 classes
  • 32 values
  • Packagejose-0.11
  • Exports89
  • LanguageHaskell2010
  • LicenceApache-2.0
  • SourceJWK.hs

JWK generation

6 declarations
datadata Crv
#

"crv" (Curve) Parameter

Instances5Eq, Ord, Show, FromJSON, ToJSON
  • Eq CrvDefined in jose-0.11 · Crypto.JOSE.JWA.JWK
  • Ord CrvDefined in jose-0.11 · Crypto.JOSE.JWA.JWK
  • Show CrvDefined in jose-0.11 · Crypto.JOSE.JWA.JWK
  • FromJSON CrvDefined in jose-0.11 · Crypto.JOSE.JWA.JWK
  • ToJSON CrvDefined in jose-0.11 · Crypto.JOSE.JWA.JWK
datadata JWK
#

RFC 7517 §4. JSON Web Key (JWK) Format

Instances6Eq, Show, FromJSON, ToJSON, AsPublicKey, VerificationKeyStore

Parts of a JWK

13 declarations
datadata KeyUse
#

RFC 7517 §4.2. "use" (Public Key Use) Parameter

Instances5Eq, Ord, Show, FromJSON, ToJSON
datadata JWKAlg
#

RFC 7517 §4.4. "alg" (Algorithm) Parameter

See also RFC 7518 §6.4. which states that for "oct" keys, an "alg" member SHOULD be present to identify the algorithm intended to be used with the key, unless the application uses another means or convention to determine the algorithm used.

Constructors

Instances4Eq, Show, FromJSON, ToJSON

Converting from other key formats

4 declarations

JWK Thumbprint

63 declarations
datadata SHA512
#

SHA512 cryptographic hash algorithm

Instances8Data, Show, HashAlgorithm, HashAlgorithmPrefix, HashAlgorithmASN1, HashBlockSize, …
newtypenewtype Digest a
#

Represent a digest for a given hash algorithm.

This type is an instance of ByteArrayAccess from package memory. Module Data.ByteArray provides many primitives to work with those values including conversion to other types.

Creating a digest from a bytearray is also possible with function digestFromByteString.

Instances7Eq, Data, Ord, Read, Show, NFData, …
newtypenewtype Context a
#

Represent a context for a given hash algorithm.

This type is an instance of ByteArrayAccess for debugging purpose. Internal layout is architecture dependent, may contain uninitialized data fragments, and change in future versions. The bytearray should not be used as input to cryptographic algorithms.

Instances2NFData, ByteArrayAccess
classclass HashAlgorithm a where
#

Class representing hashing algorithms.

The interface presented here is update in place and lowlevel. the Hash module takes care of hidding the mutable interface properly.

Methods

Instances44HashAlgorithm, …
datadata Blake2b (bitlen :: Nat)
#

Fast cryptographic hash.

It is especially known to target 64bits architectures.

Known supported digest sizes:

  • Blake2b 160

  • Blake2b 224

  • Blake2b 256

  • Blake2b 384

  • Blake2b 512

Instances7Data, Show, HashAlgorithm, HashBlake2, HashBlockSize, HashDigestSize, …
datadata Blake2bp (bitlen :: Nat)
#
Instances7Data, Show, HashAlgorithm, HashBlake2, HashBlockSize, HashDigestSize, …
datadata Blake2s (bitlen :: Nat)
#

Fast and secure alternative to SHA1 and HMAC-SHA1

It is espacially known to target 32bits architectures.

Known supported digest sizes:

  • Blake2s 160

  • Blake2s 224

  • Blake2s 256

Instances7Data, Show, HashAlgorithm, HashBlake2, HashBlockSize, HashDigestSize, …
datadata Blake2sp (bitlen :: Nat)
#
Instances7Data, Show, HashAlgorithm, HashBlake2, HashBlockSize, HashDigestSize, …
classclass HashAlgorithm a => HashAlgorithmPrefix a where
#

Hashing algorithms with a constant-time implementation.

Instances6HashAlgorithmPrefix
datadata Blake2b_160
#

Blake2b (160 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Blake2b_224
#

Blake2b (224 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Blake2b_256
#

Blake2b (256 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Blake2b_384
#

Blake2b (384 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Blake2b_512
#

Blake2b (512 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Blake2bp_512
#

Blake2bp (512 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Blake2s_160
#

Blake2s (160 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Blake2s_224
#

Blake2s (224 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Blake2s_256
#

Blake2s (256 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Blake2sp_224
#

Blake2sp (224 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Blake2sp_256
#

Blake2sp (256 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Keccak_224
#

Keccak (224 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Keccak_256
#

Keccak (256 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Keccak_384
#

Keccak (384 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Keccak_512
#

Keccak (512 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata MD2
#

MD2 cryptographic hash algorithm

Instances7Data, Show, HashAlgorithm, HashAlgorithmASN1, HashBlockSize, HashDigestSize, …
datadata MD4
#

MD4 cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata MD5
#

MD5 cryptographic hash algorithm

Instances8Data, Show, HashAlgorithm, HashAlgorithmPrefix, HashAlgorithmASN1, HashBlockSize, …
datadata RIPEMD160
#

RIPEMD160 cryptographic hash algorithm

Instances7Data, Show, HashAlgorithm, HashAlgorithmASN1, HashBlockSize, HashDigestSize, …
datadata SHA1
#

SHA1 cryptographic hash algorithm

Instances8Data, Show, HashAlgorithm, HashAlgorithmPrefix, HashAlgorithmASN1, HashBlockSize, …
datadata SHA224
#

SHA224 cryptographic hash algorithm

Instances8Data, Show, HashAlgorithm, HashAlgorithmPrefix, HashAlgorithmASN1, HashBlockSize, …
datadata SHA256
#

SHA256 cryptographic hash algorithm

Instances8Data, Show, HashAlgorithm, HashAlgorithmPrefix, HashAlgorithmASN1, HashBlockSize, …
datadata SHA3_224
#

SHA3 (224 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata SHA3_256
#

SHA3 (256 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata SHA3_384
#

SHA3 (384 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata SHA3_512
#

SHA3 (512 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata SHA384
#

SHA384 cryptographic hash algorithm

Instances8Data, Show, HashAlgorithm, HashAlgorithmPrefix, HashAlgorithmASN1, HashBlockSize, …
datadata SHA512t_224
#

SHA512t (224 bits) cryptographic hash algorithm

Instances7Data, Show, HashAlgorithm, HashAlgorithmASN1, HashBlockSize, HashDigestSize, …
datadata SHA512t_256
#

SHA512t (256 bits) cryptographic hash algorithm

Instances7Data, Show, HashAlgorithm, HashAlgorithmASN1, HashBlockSize, HashDigestSize, …
datadata SHAKE128 (bitlen :: Nat)
#

SHAKE128 (128 bits) extendable output function. Supports an arbitrary digest size, to be specified as a type parameter of kind Nat.

Note: outputs from SHAKE128 n and SHAKE128 m for the same input are correlated (one being a prefix of the other). Results are unrelated to SHAKE256 results.

Instances7Data, Show, HashAlgorithm, HashSHAKE, HashBlockSize, HashDigestSize, …
datadata SHAKE256 (bitlen :: Nat)
#

SHAKE256 (256 bits) extendable output function. Supports an arbitrary digest size, to be specified as a type parameter of kind Nat.

Note: outputs from SHAKE256 n and SHAKE256 m for the same input are correlated (one being a prefix of the other). Results are unrelated to SHAKE128 results.

Instances7Data, Show, HashAlgorithm, HashSHAKE, HashBlockSize, HashDigestSize, …
datadata Skein256_224
#

Skein256 (224 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Skein256_256
#

Skein256 (256 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Skein512_224
#

Skein512 (224 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Skein512_256
#

Skein512 (256 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Skein512_384
#

Skein512 (384 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Skein512_512
#

Skein512 (512 bits) cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Tiger
#

Tiger cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize
datadata Whirlpool
#

Whirlpool cryptographic hash algorithm

Instances6Data, Show, HashAlgorithm, HashBlockSize, HashDigestSize, HashInternalContextSize

Update the context with the first N bytes of a bytestring and return the digest. The code path is independent from N but much slower than a normal hashUpdate. The function can be called for the last bytes of a message, in order to exclude a variable padding, without leaking the padding length. The begining of the message, never impacted by the padding, should preferably go through hashUpdate for better performance.

JWK Set

3 declarations
newtypenewtype JWKSet
#

RFC 7517 §5. JWK Set Format

Constructors

Instances5Eq, Show, FromJSON, ToJSON, VerificationKeyStore
valuecheckJWK :: (MonadError e m, AsError e) => JWK -> m ()
#

Sanity-check a JWK.

Return an appropriate error if the key is size is too small to be used with any JOSE algorithm, or for other problems that mean the key cannot be used.

valuebestJWSAlg :: (MonadError e m, AsError e) => JWK -> m Alg
#

Choose the cryptographically strongest JWS algorithm for a given key. The JWK "alg" algorithm parameter is ignored.