Sample code for 30+ languages & platforms
Objective-C

Create JWT using a Brainpool EC Key

See more JSON Web Token (JWT) Examples

Demonstrates how to create a JWT using an EC private key. This is for JOSE headers having an "alg" member with any of the following values:
  • BP160R1
  • BP192R1
  • BP224R1
  • BP256R1
  • BP320R1
  • BP384R1
  • BP512R1

This example also demonstrates how to include time constraints:

  • nbf: Not Before Time
  • exp: Expiration Time
  • iat: Issue At Time

Chilkat Objective-C Downloads

Objective-C
#import <CkoPrivateKey.h>
#import <CkoJwt.h>
#import <CkoJsonObject.h>
#import <NSString.h>

BOOL success = NO;

// Demonstrates how to create a JWT using a brainpool EC private key.

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

CkoPrivateKey *privKey = [[CkoPrivateKey alloc] init];

// Load a brainpool EC key.
success = [privKey LoadPemFile: @"c:/qa_data/pem/ec_brainpool_privKey.pem"];
if (success != YES) {
    NSLog(@"%@",privKey.LastErrorText);
    return;
}

// You can examine the curve name of the key you just loaded by getting the private in XML format:
// <ECCKeyValue curve="CURVE_NAME">...</ECCKeyValue>
NSLog(@"%@",[privKey GetXml]);

CkoJwt *jwt = [[CkoJwt alloc] init];

// Build the JOSE header
CkoJsonObject *jose = [[CkoJsonObject alloc] init];
// Use the brainpool curve name matching the private key you just loaded.
// Use "BP256R1", or "BP384R1", etc.   
success = [jose AppendString: @"alg" value: @"BP256R1"];
success = [jose AppendString: @"typ" value: @"JWT"];

// Now build the JWT claims (also known as the payload)
CkoJsonObject *claims = [[CkoJsonObject alloc] init];
success = [claims AppendString: @"iss" value: @"http://example.org"];
success = [claims AppendString: @"sub" value: @"John"];
success = [claims AppendString: @"aud" value: @"http://example.com"];

// Set the timestamp of when the JWT was created to now.
int curDateTime = [[jwt GenNumericDate: [NSNumber numberWithInt: 0]] intValue];
success = [claims AddIntAt: [NSNumber numberWithInt: -1] name: @"iat" value: [NSNumber numberWithInt: curDateTime]];

// Set the "not process before" timestamp to now.
success = [claims AddIntAt: [NSNumber numberWithInt: -1] name: @"nbf" value: [NSNumber numberWithInt: curDateTime]];

// Set the timestamp defining an expiration time (end time) for the token
// to be now + 1 hour (3600 seconds)
success = [claims AddIntAt: [NSNumber numberWithInt: -1] name: @"exp" value: [NSNumber numberWithInt: (curDateTime + 3600)]];

// Produce the smallest possible JWT:
jwt.AutoCompact = YES;

// Create the JWT token.  This is where the ECC signature is created.
NSString *token = [jwt CreateJwtPk: [jose Emit] payload: [claims Emit] key: privKey];

NSLog(@"%@",token);