Sample code for 30+ languages & platforms
Delphi DLL

Create JWT using a Brainpool EC Key

See more JSON Web Token (JWT) Examples

Demonstrates how to create a JWT using an EC private key. This is for JOSE headers having an "alg" member with any of the following values:
  • BP160R1
  • BP192R1
  • BP224R1
  • BP256R1
  • BP320R1
  • BP384R1
  • BP512R1

This example also demonstrates how to include time constraints:

  • nbf: Not Before Time
  • exp: Expiration Time
  • iat: Issue At Time

Chilkat Delphi DLL Downloads

Delphi DLL
uses
    Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
    Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, PrivateKey, Jwt, JsonObject;

...

procedure TForm1.Button1Click(Sender: TObject);
var
success: Boolean;
privKey: HCkPrivateKey;
jwt: HCkJwt;
jose: HCkJsonObject;
claims: HCkJsonObject;
curDateTime: Integer;
token: PWideChar;

begin
success := False;

// Demonstrates how to create a JWT using a brainpool EC private key.

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

privKey := CkPrivateKey_Create();

// Load a brainpool EC key.
success := CkPrivateKey_LoadPemFile(privKey,'c:/qa_data/pem/ec_brainpool_privKey.pem');
if (success <> True) then
  begin
    Memo1.Lines.Add(CkPrivateKey__lastErrorText(privKey));
    Exit;
  end;

// You can examine the curve name of the key you just loaded by getting the private in XML format:
// <ECCKeyValue curve="CURVE_NAME">...</ECCKeyValue>
Memo1.Lines.Add(CkPrivateKey__getXml(privKey));

jwt := CkJwt_Create();

// Build the JOSE header
jose := CkJsonObject_Create();
// Use the brainpool curve name matching the private key you just loaded.
// Use "BP256R1", or "BP384R1", etc.   
success := CkJsonObject_AppendString(jose,'alg','BP256R1');
success := CkJsonObject_AppendString(jose,'typ','JWT');

// Now build the JWT claims (also known as the payload)
claims := CkJsonObject_Create();
success := CkJsonObject_AppendString(claims,'iss','http://example.org');
success := CkJsonObject_AppendString(claims,'sub','John');
success := CkJsonObject_AppendString(claims,'aud','http://example.com');

// Set the timestamp of when the JWT was created to now.
curDateTime := CkJwt_GenNumericDate(jwt,0);
success := CkJsonObject_AddIntAt(claims,-1,'iat',curDateTime);

// Set the "not process before" timestamp to now.
success := CkJsonObject_AddIntAt(claims,-1,'nbf',curDateTime);

// Set the timestamp defining an expiration time (end time) for the token
// to be now + 1 hour (3600 seconds)
success := CkJsonObject_AddIntAt(claims,-1,'exp',curDateTime + 3600);

// Produce the smallest possible JWT:
CkJwt_putAutoCompact(jwt,True);

// Create the JWT token.  This is where the ECC signature is created.
token := CkJwt__createJwtPk(jwt,CkJsonObject__emit(jose),CkJsonObject__emit(claims),privKey);

Memo1.Lines.Add(token);

CkPrivateKey_Dispose(privKey);
CkJwt_Dispose(jwt);
CkJsonObject_Dispose(jose);
CkJsonObject_Dispose(claims);

end;