Sample code for 30+ languages & platforms
Objective-C

Create JWT using a Certificate's Private Key

See more JSON Web Token (JWT) Examples

Demonstrates how to create a JWT using a certificate's private key.

Chilkat Objective-C Downloads

Objective-C
#import <CkoCert.h>
#import <CkoJwt.h>
#import <CkoJsonObject.h>
#import <NSString.h>

BOOL success = NO;

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

// Demonstrates how to create a JWT using an certificate's private key.

CkoCert *cert = [[CkoCert alloc] init];

// Load an ECC private key from a PEM file.
success = [cert LoadPfxFile: @"c:/temp/myPfx.pfx" password: @"pfxPassword"];
if (success != YES) {
    NSLog(@"%@",cert.LastErrorText);
    return;
}

CkoJwt *jwt = [[CkoJwt alloc] init];

// Build the JOSE header
CkoJsonObject *jose = [[CkoJsonObject alloc] init];
// Note: The IsEcdsa function was added in Chilkat v10.1.0
if ([cert IsEcdsa] == YES) {
    // Use ES256.  Pass the string "ES384" or "ES512" to use ECC with SHA-384 or SHA-512.
    [jose AppendString: @"alg" value: @"ES256"];
}
else {
    // Probably RSA...
    // Use RS256.  Pass the string "RS384" or "RS512" to use RSA with SHA-384 or SHA-512.
    [jose AppendString: @"alg" value: @"RS256"];
}

[jose AppendString: @"typ" value: @"JWT"];

// Now build the JWT claims (also known as the payload)
CkoJsonObject *claims = [[CkoJsonObject alloc] init];
[claims AppendString: @"iss" value: @"http://example.org"];
[claims AppendString: @"sub" value: @"John"];
[claims AppendString: @"aud" value: @"http://example.com"];

// Set the timestamp of when the JWT was created to now.
int curDateTime = [[jwt GenNumericDate: [NSNumber numberWithInt: 0]] intValue];
[claims AddIntAt: [NSNumber numberWithInt: -1] name: @"iat" value: [NSNumber numberWithInt: curDateTime]];

// Set the "not process before" timestamp to now.
[claims AddIntAt: [NSNumber numberWithInt: -1] name: @"nbf" value: [NSNumber numberWithInt: curDateTime]];

// Set the timestamp defining an expiration time (end time) for the token
// to be now + 1 hour (3600 seconds)
[claims AddIntAt: [NSNumber numberWithInt: -1] name: @"exp" value: [NSNumber numberWithInt: (curDateTime + 3600)]];

// Produce the smallest possible JWT:
jwt.AutoCompact = YES;

// Create the JWT token.
NSString *token = [jwt CreateJwtCert: [jose Emit] payload: [claims Emit] cert: cert];

NSLog(@"%@",token);

// Example output:
// eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJodHRwOi8vZXhhbXBsZS5vcmciLCJzdWIiOiJKb2huIiwiYXVkIjoiaHR0cDovL2V4YW1wbGUuY29tIiwiaWF0IjoxNDg1NzA4NzkyLCJuYmYiOjE0ODU3MDg3OTIsImV4cCI6MTQ4NTcxMjM5Mn0.wqsuyJpxJ073ox-lOiLFqG1lQocXe4hGf2XGZJRrO3qn0UusxI_bu3Gzky8gBsH4sA4u9TWZn5M-1wYMMIJk6Q