Creates and parses JSON Web Tokens (JWTs) and JSON Web Keys (JWKs) for an account, and generates RSA key pairs for signing them. Registered as the "jwtManager" service so app scripts can build and sign a JwtBuilder, parse an incoming token with a JwtParserBuilder, or generate a new RSA key pair for a signing key that is then stored in secure storage. Signing parameters (issuer, subject, algorithm and key) can be pulled directly from secure storage by key name so scripts do not need to handle key material themselves.
Group: Managers
Methods
newJwtBuilder(String secureParamsKey)
Returns: JwtBuilder
Returns a new JwtBuilder that can be configured and then used to create JWT compact serialized strings. If the given secure storage key holds a params map, the builder is pre-populated with the issuer, subject, and a signing key parsed from the stored signature algorithm and signature key entries. If the key is missing or the stored map is empty, an unconfigured builder is returned.
| Parameter | Description |
|---|---|
secureParamsKey | the secure storage key holding the JWT signing parameters, or null/absent for no defaults |
newJwtBuilder()
Returns: JwtBuilder
Returns a new, unconfigured JwtBuilder that can be configured and then used to create JWT compact serialized strings.
newJwtParserBuilder()
Returns: JwtParserBuilder
Returns a new JwtParserBuilder that can be configured with a signing/verification key and then used to parse and validate a compact JWT string.
parseJsonWebKeySet(String json)
Returns: JsonWebKeySet
Parses a JSON Web Key Set from its JSON string representation.
| Parameter | Description |
|---|---|
json | the JSON text of a JWK set, as produced by an identity provider or key generation tool |
getSignatureAlgorithm(String name)
Returns: SignatureAlgorithm
Looks up the SignatureAlgorithm matching the given name, such as "RS256" or "HS256", using a case-insensitive comparison.
| Parameter | Description |
|---|---|
name | the JWA signature algorithm name to look up |
parsePrivateKey(String key)
Returns: PrivateKey
Parses an RSA private key from its PEM text, tolerating surrounding whitespace and PEM header/footer lines before parsing.
| Parameter | Description |
|---|---|
key | the PEM-encoded RSA private key text |
generateRsaJwkKeyPair(int keysize)
Returns: Map<String,Object>
Generates a new RSA public/private key pair of the given size and returns it in both JWK and PEM forms. This is an expensive, CPU-bound operation. The returned map has three entries: "publicKeyJWK" (the public key as a JWK params map), "publicKeyPEM" (the public key as PEM text) and "privateKeyPEM" (the private key as PEM text).
| Parameter | Description |
|---|---|
keysize | the RSA key size in bits, for example 2048 |