ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
jwt.h File Reference

JSON Web Token verification, HS256: RFC 7519 claims carried in an RFC 7515 JWS. More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

JSON Web Token verification, HS256: RFC 7519 claims carried in an RFC 7515 JWS.

A token arrives in the JWS Compact Serialization (RFC 7515 sec 7.1), ‘BASE64URL(UTF8(JWS Protected Header)) || ’.' || BASE64URL(JWS Payload) || '.' || BASE64URL(JWS Signature), normally insideAuthorization: Bearer <token>` (RFC 6750 sec 2.1). The verifier recomputes the MAC over the JWS Signing Input (RFC 7515 sec 2), compares it against the signature segment in constant time (RFC 7518 sec 3.2), and reads claims out of the payload (RFC 7519 sec 4).

Only HS256 is served: that alg value is HMAC using SHA-256 (RFC 7518 sec 3.1), and the JOSE header's alg is required to name it before any MAC is computed (RFC 7515 sec 4.1.1, RFC 8725 sec 3.1), which rejects none and every other algorithm substitution. RS256 ID tokens belong to the OIDC module. Every segment decodes with the URL and filename safe alphabet, padding skipped (RFC 4648 sec 5).

The base calls judge the signature alone. The _at calls also judge exp (RFC 7519 sec 4.1.4) and nbf (sec 4.1.5) against a caller-supplied NumericDate (sec 2) with a skew leeway; iat (sec 4.1.6) is read like any other integer claim. Nothing here allocates: every buffer is a local of the call that fills it, and the whole path runs on a host build.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file jwt.h.