Crypto Middleware
    Preparing search index...

    Function verifyJwt

    • Verify a JWT (HS256 only) using HMAC-SHA256.

      This is a minimal JWT verifier intended for middleware use cases. For production systems requiring RS256/ES256 or full JOSE support, consider using a dedicated JWT library.

      Parameters

      • jwtSecret: string

        The HMAC secret (UTF-8 string or hex-encoded key).

      • token: string

        The raw JWT string (header.payload.signature).

      Returns JwtPayload

      The decoded JWT payload.

      On invalid/expired tokens.

      const token = req.headers.authorization?.replace("Bearer ", "") ?? "";
      const payload = verifyJwt("my-hs256-secret", token);
      console.log(payload.sub); // "user-123"