Skip to content

Variable: StandardJwt ​

const StandardJwt: object

Defined in: jwt.ts:278

RFC 9964 ML-DSA JWTs: interoperable with any compliant JOSE implementation.

Type Declaration ​

generateKeyPair() ​

readonly generateKeyPair(alg?, options?): object

Generates an ML-DSA key pair as AKP JWKs. The private JWK contains the secret seed as a string (inherent to JWK): store it as carefully as any secret key.

Parameters ​

alg? ​

MlDsaJoseAlg = ...

options? ​
kid? ​

string

Returns ​

object

privateJwk ​

privateJwk: AkpJwk

publicJwk ​

publicJwk: AkpJwk

publicJwk() ​

readonly publicJwk(privateJwk): AkpJwk

Derives the public JWK from a private one.

Parameters ​

privateJwk ​

AkpJwk

Returns ​

AkpJwk

sign() ​

readonly sign(claims, privateJwk, options?): string

Signs claims as a compact JWS (alg = the key's ML-DSA level).

Parameters ​

claims ​

JwtClaims

privateJwk ​

AkpJwk

options? ​

StandardSignOptions = {}

Returns ​

string

verify() ​

readonly verify(token, publicJwk, options?): JwtClaims

Verifies a compact JWS against publicJwk and returns the claims. The algorithm is taken from the key and must equal the header alg; crit headers are rejected.

Parameters ​

token ​

string

publicJwk ​

AkpJwk

options? ​

StandardVerifyOptions = {}

Returns ​

JwtClaims

Throws ​

for an invalid signature or failed claim check.

Apache-2.0.