10 releases

0.3.5 Apr 21, 2022
0.3.4 Jul 28, 2021
0.3.2 Apr 28, 2021
0.3.1 Jan 26, 2021
0.0.3 Jul 13, 2020

#387 in Authentication

Download history 32879/week @ 2025-03-09 33308/week @ 2025-03-16 32580/week @ 2025-03-23 30019/week @ 2025-03-30 34200/week @ 2025-04-06 27083/week @ 2025-04-13 27651/week @ 2025-04-20 33358/week @ 2025-04-27 31685/week @ 2025-05-04 26451/week @ 2025-05-11 29458/week @ 2025-05-18 31165/week @ 2025-05-25 34136/week @ 2025-06-01 31673/week @ 2025-06-08 25407/week @ 2025-06-15 25212/week @ 2025-06-22

116,839 downloads per month
Used in 19 crates (9 directly)

MIT license

53KB
1K SLoC

jsonwebkey

crates.io docs.rs codecov

JSON Web Key (JWK) (de)serialization, generation, and conversion.

Goals

tl;dr: get keys into a format that can be used by other crates; be as safe as possible while doing so.

  • Serialization and deserialization of Required and Recommended key types (HS256, RS256, ES256)
  • Conversion to PEM for interop with existing JWT libraries (e.g., jsonwebtoken)
  • Key generation (particularly useful for testing)

Non-goals

  • be a fully-featured JOSE framework

Examples

Deserializing from JSON

extern crate jsonwebkey as jwk;
// Generated using https://mkjwk.org/.
let jwt_str = r#"{
   "kty": "oct",
   "use": "sig",
   "kid": "my signing key",
   "k": "Wpj30SfkzM_m0Sa_B2NqNw",
   "alg": "HS256"
}"#;
let the_jwk: jwk::JsonWebKey = jwt_str.parse().unwrap();
println!("{:#?}", the_jwk); // looks like `jwt_str` but with reordered fields.

Using with other crates

#[cfg(all(feature = "generate", feature = "jwt-convert"))] {
extern crate jsonwebtoken as jwt;
extern crate jsonwebkey as jwk;

#[derive(serde::Serialize, serde::Deserialize)]
struct TokenClaims {
   exp: usize
}

let mut my_jwk = jwk::JsonWebKey::new(jwk::Key::generate_p256());
my_jwk.set_algorithm(jwk::Algorithm::ES256);

let alg: jwt::Algorithm = my_jwk.algorithm.unwrap().into();
let token = jwt::encode(
    &jwt::Header::new(alg),
    &TokenClaims { exp: 1492 },
    &my_jwk.key.to_encoding_key(),
).unwrap();

let mut validation = jwt::Validation::new(alg);
validation.validate_exp = false;
jwt::decode::<TokenClaims>(&token, &my_jwk.key.to_decoding_key(), &validation).unwrap();
}

Features

  • pkcs-convert - enables Key::{to_der, to_pem}. This pulls in the yasna crate.
  • generate - enables Key::{generate_p256, generate_symmetric}. This pulls in the p256 and rand crates.
  • jwt-convert - enables conversions to types in the jsonwebtoken crate.

Dependencies

~1.4–5.5MB
~118K SLoC