Stars: 486
Forks: 94
Pull Requests: 243
Issues: 0
Watchers: 31
Last Updated: 2020-09-22 08:52:44
:closed_lock_with_key: JSON Object Signing and Encryption Framework (JWT, JWS, JWE, JWA, JWK, JWKSet and more)
License: MIT License
Languages: PHP, Shell
If you really love that library, then you can help me out for a couple of 🍻!
We highly recommend you to use the new JWT Framework project instead of this library.
A migration guide will be/is available in the documentation of the new project.
This library provides an implementation of:
JWS or JWE objects support every input that can be encoded into JSON:
string
, array
, integer
, float
...\JsonSerializable
interface such as JWKInterface
or JWKSetInterface
The detached content is also supported.
Unencoded payload is supported. This means you can sign and verify payload without base64 encoding operation.
As per the RFC7797, the b64
header MUST be protected.
When b64
header is set, the crit
protected header with value b64
in its array of values is mandatory.
Compression Method | Supported | Comment |
---|---|---|
Deflate (DEF ) |
YES | |
GZip (GZ ) |
YES | This compression method is not described in the specification |
ZLib (ZLIB ) |
YES | This compression method is not described in the specification |
Key Type | Supported | Comment |
---|---|---|
none |
YES | None keys are for the none algorithm only |
oct |
YES | Symmetric keys |
RSA |
YES | RSA based asymmetric keys |
EC |
YES | Elliptic Curves based asymmetric keys |
OKP |
YES | Octet Key Pair based asymmetric keys |
JWK objects support JSON Web Key Thumbprint (RFC 7638).
JWKSet is fully supported.
Signature Algorithm | Supported | Comment |
---|---|---|
HS256 , HS384 and HS512 |
YES | |
HS256 , ES384 and ES512 |
YES | |
RS256 , RS384 and RS512 |
YES | |
PS256 , PS384 and PS512 |
YES | |
none |
YES | Please note that this is not a secured algorithm. USE IT WITH CAUTION! |
EdDSA with Ed25519 curve |
YES | Third party extension required |
EdDSA with Ed448 curve |
NO |
Please note that the EdDSA signature algorithm specification
is not not yet approved. Support for algorithms Ed25518
and Ed448
may change. Use with caution.
Key Encryption Algorithm | Supported | Comment |
---|---|---|
dir |
YES | |
RSA1_5 , RSA-OAEP and RSA-OAEP-256 |
YES | |
ECDH-ES , ECDH-ES+A128KW , ECDH-ES+A192KW and ECDH-ES+A256KW |
YES | |
A128KW , A128KW and A128KW |
YES | |
PBES2-HS256+A128KW , PBES2-HS384+A192KW and PBES2-HS512+A256KW |
YES | |
A128GCMKW , A192GCMKW and A256GCMKW |
YES | For better performance, please use PHP 7.1+ or this third party extension |
EdDSA with X25519 curve |
YES | Third party extension required |
EdDSA with X448 curve |
NO |
Please note that the EdDSA encryption algorithm specification
is not not yet approved. Support for algorithms X25518
and X448
may change. Use with caution.
Content Encryption Algorithm | Supported | Comment |
---|---|---|
A128CBC-HS256 , A192CBC-HS384 and A256CBC-HS512 |
YES | |
A128GCM , A192GCM and A256GCM |
YES | For better performance, please use PHP 7.1+ or this third party extension |
The release process is described here.
This library needs at least:
Please consider the following optional requirements:
AxxxGCM
and AxxxGCMKW
) if not on PHP 7.1+: PHP Crypto Extension (at least v0.2.1
) is highly recommended as encryption/decryption is faster than the pure PHP implementation.Please read performance test results below concerning the ECC based algorithms. As the time needed to perform operation is long compared to the other algorithms, we do not recommend their use.
It has been successfully tested using PHP 7.0
, PHP 7.1
and PHP7.2
with all algorithms.
If you use PHP 5.6, please install the version ^6.0 of this project.
Tests vectors from the RFC 7520 are fully implemented and all tests pass.
We also track bugs and code quality using Scrutinizer-CI and Sensio Insight.
Coding Standards are verified by StyleCI.
Code coverage is analyzed by Coveralls.io.
The preferred way to install this library is to rely on Composer:
composer require spomky-labs/jose
Have a look at How to use to know how to load your JWT and discover all possibilities provided by this library.
Please read the performance page to know how fast are the algorithms supported by this library.
Requests for new features, bug fixed and all other ideas to make this library useful are welcome. If you feel comfortable writting code, you could try to fix opened issues where help is wanted or those that are easy to fix.
Do not forget to follow these best practices.
This software is release under MIT licence.