SHARE ON

Ever wondered how JWT came to be and what problems it was designed to tackle?
Are you curious about the plethora of algorithms available for signing and encrypting JWTs?
Or are you interested in getting up-to-speed with JWTs as soon as possible? Then this handbook is for you.
## Contents
1. Special Thanks `4`
1. Introduction `5`
1. What is a JSON WebToken? `5`
1. What problem does it solve? `6`
1. A little bit of history `6`
1. Practical Applications `8`
1. Client-side/Stateless Sessions `8`
1. Security Considerations `9`
1. Signature Stripping `9`
1. Cross-Site Request Forgery (CSRF) `10`
1. Cross-Site Scripting (XSS) `11`
1. Are Client-Side Sessions Useful? `13`
1. Example `13`
1. FederatedIdentity `16`
1. Access and Refresh Tokens `18`
1. JWTs and OAuth2 `19`
1. JWTs and OpenID Connect `20`
1. OpenID Connect Flows and JWTs `20`
1. Example `20`
1. Setting up Auth0 Lock for Node.js Applications `21`
1. JSON Web Tokens in Detail `23`
1. The Header `24`
1. The Payload `25`
1. Registered Claims `25`
1. Public and Private Claims `26`
1. Unsecured JWTs `27`
1. Creating an Unsecured JWT `27`
1. Sample Code `28`
1. Parsing an Unsecured JWT `28`
1. Sample Code `29`
1. JSON Web Signatures `30`
1. Structure of a Signed JWT `30`
1. Algorithm Overview for Compact Serialization `32`
1. Practical Aspects of Signing Algorithms `33`
1. JWS Header Claims `36`
1. JWS JSON Serialization `36`
1. Flattened JWS JSON Serialization `38`
1. Signing and Validating Tokens `38`
1. HS256: HMAC 1. SHA-256 `39`
1. RS256: RSASSA 1. SHA256 `39`
1. ES256: ECDSA using P-256 and SHA-256 `40`
1. JSON Web Encryption (JWE) `41`
1. Structure of an Encrypted JWT `44`
1. Key Encryption Algorithms `45`
1. Key Management Modes `46`
1. Content Encryption Key (CEK) and JWE Encryption Key `47`
1. Content Encryption Algorithms `48`
1. The Header `48`
1. Algorithm Overview for Compact Serialization `49`
1. JWE JSON Serialization `50`
1. Flattened JWE JSON Serialization `52`
1. Encrypting and Decrypting Tokens `52`
1. Introduction: Managing Keys with node-jose `52`
1. AES-128 Key Wrap (Key) 1. AES-128 GCM (Content) `54`
1. RSAES-OAEP (Key) 1. AES-128 CBC 1. SHA-256 (Content) `54`
1. ECDH-ESP-256 (Key)1. AES-128 GCM (Content) `55`
1. Nested JWT: ECDSA using P-256 and SHA-256 (Signature) 1. RSAES-OAEP (Encrypted Key) 1. AES-128 CBC 1. SHA-256 (Encrypted Content) `55`
1. Decryption `56`
1. JSON Web Keys (JWK) `58`
1. Structure of a JSON Web Key `59`
1. JSON Web Key Set `60`
1. JSON Web Algorithms `61`
1. General Algorithms `61`
1. Base64 `61`
1. Base64-URL `63`
1. Sample Code `63`
1. SHA `64`
1. Signing Algorithms `69`
1. HMAC `69`
1. HMAC 1. SHA256 (HS256) `71`
1. RSA `73`
1. Choosing e, d and n `75`
1. Basic Signing `76`
1. RS256: RSASSA PKCS1 v1.5 using SHA-256 `76`
1. Algorithm `76`
1. EMSA-PKCS1-v1_5 primitive `78`
1. OS2IP primitive `79`
1. RSASP1 primitive `79`
1. RSAVP1 primitive `80`
1. I2OSP primitive `80`
1. Samplecode `81`
1. PS256: RSASSA-PSS using SHA-256 and MGF1 with SHA-256 `86`
1. Algorithm `86`
1. MGF1: the mask generation function `87`
1. EMSA-PSS-ENCODE primitive `88`
1. EMSA-PSS-VERIFY primitive `89`
1. Sample code `91`
1. Elliptic Curve `94`
1. Elliptic-Curve Arithmetic `96`
1. Point Addition `96`
1. Point Doubling `97`
1. Scalar Multiplication `97`
1. Elliptic-Curve Digital Signature Algorithm (ECDSA) `98`
1. Elliptic-Curve Domain Parameters `100`
1. Public and Private Keys `101`
1. The Discrete Logarithm Problem `101`
1. ES256: ECDSA using P-256 and SHA-256 `101`
1. Future Updates `104`
Hosted By

Sebastián Peyrott
Profitieren Sie von einer erstklassigen Customer Identity-Lösung mit integrierter Sicherheit.