Class Jwt

java.lang.Object
com.codename1.backend.security.oauth2.jwt.Jwt

public final class Jwt extends Object

A JSON Web Token whose signature has been made or verified: its text, the headers of its signature and its claims.

Jwt jwt = decoder.decode(token);
String user = jwt.getSubject();
List<String> groups = jwt.getClaimAsStringList("groups");

Times are seconds since the epoch, as the token carries them. This is not com.codename1.backend.Jwt, the helper for HS256 tokens a server issues to itself.

  • Constructor Details

    • Jwt

      public Jwt(String tokenValue, Map<String,Object> headers, Map<String,Object> claims)
      Parameters:
      tokenValue - the token as it travels
      headers - the JOSE header
      claims - the payload
  • Method Details

    • getTokenValue

      public String getTokenValue()
      The token as it travels: three base64url parts joined by dots.
    • getHeaders

      public Map<String,Object> getHeaders()
      The JOSE header: alg, and kid and typ when the token has them.
    • getClaims

      public Map<String,Object> getClaims()
    • getClaim

      public Object getClaim(String claim)
      A claim as the JSON had it: a String, a Long or Double, a Boolean, a List or a Map; null when the token has none of that name.
    • hasClaim

      public boolean hasClaim(String claim)
    • getClaimAsString

      public String getClaimAsString(String claim)
      A claim as text; null when the token has none of that name.
    • getClaimAsBoolean

      public Boolean getClaimAsBoolean(String claim)
      A claim that is true or false, or the text of either; null otherwise.
    • getClaimAsLong

      public Long getClaimAsLong(String claim)
      A numeric claim as a whole number; null when the token has none of that name or it is not a number.
    • getClaimAsStringList

      public List<String> getClaimAsStringList(String claim)
      A claim that is a list, or one value standing for a list of one: every element as text. Null when the token has none of that name.
    • getIssuer

      public String getIssuer()
      iss: who issued the token.
    • getSubject

      public String getSubject()
      sub: whom the token is about.
    • getAudience

      public List<String> getAudience()
      aud: whom the token is for. Empty when the token does not say.
    • getExpiresAt

      public Long getExpiresAt()
      exp in seconds since the epoch, or null.
    • getNotBefore

      public Long getNotBefore()
      nbf in seconds since the epoch, or null.
    • getIssuedAt

      public Long getIssuedAt()
      iat in seconds since the epoch, or null.
    • getId

      public String getId()
      jti: the token's own id.
    • toString

      public String toString()
      Description copied from class: Object
      Returns a string representation of the object. In general, the toString method returns a string that "textually represents" this object. The result should be a concise but informative representation that is easy for a person to read. It is recommended that all subclasses override this method. The toString method for class Object returns a string consisting of the name of the class of which the object is an instance, the at-sign character `@', and the unsigned hexadecimal representation of the hash code of the object. In other words, this method returns a string equal to the value of: getClass().getName() + '@' + Integer.toHexString(hashCode())
      Overrides:
      toString in class Object