Signs a JWT with an HMAC secret and returns the encoded token string. payload is a struct of claims (or a raw JSON string); key is the HMAC secret. When expiresIn (seconds) is given, iat (now) and exp (now + expiresIn) claims are added to a struct payload if absent. Only HMAC algorithms are supported: HS256 (default), HS384 and HS512. This is the Lucee crypto-extension name; RustCFML does not provide the Adobe createSignedJWT name.
jwtSign(payload, key [, algorithm] [, expiresIn])
→ returns string
HS256HS256HS384HS512Sign claims with a 1 hour lifetime using HS256.
token = jwtSign({ sub: "alex", role: "admin" }, "my-secret", "HS256", 3600);
writeDump(jwtDecode(token).exp != 0);
Expected Result: true
Sign with the HS512 algorithm.
token = jwtSign({ sub: "alex" }, "my-secret", "HS512");
writeDump(token);
Signup for cfbreak to stay updated on the latest news from the ColdFusion / CFML community. One email, every friday.