Sample code for 30+ languages & platforms
Tcl

Create JWT using a Certificate's Private Key

See more JSON Web Token (JWT) Examples

Demonstrates how to create a JWT using a certificate's private key.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

# This example requires the Chilkat API to have been previously unlocked.
# See Global Unlock Sample for sample code.

# Demonstrates how to create a JWT using an certificate's private key.

set cert [new_CkCert]

# Load an ECC private key from a PEM file.
set success [CkCert_LoadPfxFile $cert "c:/temp/myPfx.pfx" "pfxPassword"]
if {$success != 1} then {
    puts [CkCert_lastErrorText $cert]
    delete_CkCert $cert
    exit
}

set jwt [new_CkJwt]

# Build the JOSE header
set jose [new_CkJsonObject]

# Note: The IsEcdsa function was added in Chilkat v10.1.0
if {[CkCert_IsEcdsa $cert] == 1} then {
    # Use ES256.  Pass the string "ES384" or "ES512" to use ECC with SHA-384 or SHA-512.
    CkJsonObject_AppendString $jose "alg" "ES256"
} else {
    # Probably RSA...
    # Use RS256.  Pass the string "RS384" or "RS512" to use RSA with SHA-384 or SHA-512.
    CkJsonObject_AppendString $jose "alg" "RS256"
}

CkJsonObject_AppendString $jose "typ" "JWT"

# Now build the JWT claims (also known as the payload)
set claims [new_CkJsonObject]

CkJsonObject_AppendString $claims "iss" "http://example.org"
CkJsonObject_AppendString $claims "sub" "John"
CkJsonObject_AppendString $claims "aud" "http://example.com"

# Set the timestamp of when the JWT was created to now.
set curDateTime [CkJwt_GenNumericDate $jwt 0]
CkJsonObject_AddIntAt $claims -1 "iat" $curDateTime

# Set the "not process before" timestamp to now.
CkJsonObject_AddIntAt $claims -1 "nbf" $curDateTime

# Set the timestamp defining an expiration time (end time) for the token
# to be now + 1 hour (3600 seconds)
CkJsonObject_AddIntAt $claims -1 "exp" [expr $curDateTime + 3600]

# Produce the smallest possible JWT:
CkJwt_put_AutoCompact $jwt 1

# Create the JWT token.
set token [CkJwt_createJwtCert $jwt [CkJsonObject_emit $jose] [CkJsonObject_emit $claims] $cert]

puts "$token"

# Example output:
# eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJodHRwOi8vZXhhbXBsZS5vcmciLCJzdWIiOiJKb2huIiwiYXVkIjoiaHR0cDovL2V4YW1wbGUuY29tIiwiaWF0IjoxNDg1NzA4NzkyLCJuYmYiOjE0ODU3MDg3OTIsImV4cCI6MTQ4NTcxMjM5Mn0.wqsuyJpxJ073ox-lOiLFqG1lQocXe4hGf2XGZJRrO3qn0UusxI_bu3Gzky8gBsH4sA4u9TWZn5M-1wYMMIJk6Q

delete_CkCert $cert
delete_CkJwt $jwt
delete_CkJsonObject $jose
delete_CkJsonObject $claims