jwtVerify

Verifies a JWT's HMAC signature and returns its payload claims as a struct. Throws when the token is malformed, the signature does not match, the token's algorithm does not match the expected algorithm (when one is given, guarding against algorithm-substitution attacks), or the token is expired (exp) or not yet valid (nbf). Only HMAC algorithms are supported: HS256, HS384 and HS512. This is the Lucee crypto-extension name; RustCFML does not provide the Adobe verifySignedJWT name.

jwtVerify(token, key [, algorithm]) → returns struct

This function requires RustCFML.  Not supported on Lucee, Adobe ColdFusion, etc.

Argument Reference

token string
Required

The JWT to verify (three dot-separated base64url parts).

key string
Required

The HMAC secret key the token was signed with.

algorithm string

Optional expected algorithm (HS256, HS384 or HS512); when given, a token signed with a different algorithm is rejected.
Values:
  • HS256
  • HS384
  • HS512

Examples
Sample code invoking the jwtVerify function

Sign a token and verify it back.

token = jwtSign({ sub: "alex" }, "my-secret", "HS256", 3600);
claims = jwtVerify(token, "my-secret");
writeDump(claims.sub);

Expected Result: alex

A signature check with the wrong secret throws.

token = jwtSign({ sub: "alex" }, "my-secret");
try {
	jwtVerify(token, "other-secret");
} catch (any e) {
	writeDump(e.getMessage());
}

Expected Result: JwtVerify: signature verification failed.

Signup for cfbreak to stay updated on the latest news from the ColdFusion / CFML community. One email, every friday.

Fork me on GitHub