jwtSign

Signs a JWT with an HMAC secret and returns the encoded token string. payload is a struct of claims (or a raw JSON string); key is the HMAC secret. When expiresIn (seconds) is given, iat (now) and exp (now + expiresIn) claims are added to a struct payload if absent. Only HMAC algorithms are supported: HS256 (default), HS384 and HS512. This is the Lucee crypto-extension name; RustCFML does not provide the Adobe createSignedJWT name.

jwtSign(payload, key [, algorithm] [, expiresIn]) → returns string

This function requires RustCFML.  Not supported on Lucee, Adobe ColdFusion, etc.

Argument Reference

payload struct
Required

Struct of claims to sign (or a raw JSON string).

key string
Required

The HMAC secret key.

algorithm string
Default: HS256

HMAC algorithm: HS256 (default), HS384 or HS512.
Values:
  • HS256
  • HS384
  • HS512

expiresIn numeric

Optional lifetime in seconds; adds iat and exp claims when they are absent.

Examples
Sample code invoking the jwtSign function

Sign claims with a 1 hour lifetime using HS256.

token = jwtSign({ sub: "alex", role: "admin" }, "my-secret", "HS256", 3600);
writeDump(jwtDecode(token).exp != 0);

Expected Result: true

Sign with the HS512 algorithm.

token = jwtSign({ sub: "alex" }, "my-secret", "HS512");
writeDump(token);

Signup for cfbreak to stay updated on the latest news from the ColdFusion / CFML community. One email, every friday.

Fork me on GitHub