joserfc is a Python library that provides a comprehensive implementation of several essential JSON Object Signing and Encryption (JOSE) standards.
This package contains implementation of:
RFC7515: JSON Web Signature
RFC7516: JSON Web Encryption
RFC7517: JSON Web Key
RFC7518: JSON Web Algorithms
RFC7519: JSON Web Token
RFC7520: Examples of Protecting Content Using JSON Object Signing and Encryption
RFC7638: JSON Web Key (JWK) Thumbprint
RFC7797: JSON Web Signature (JWS) Unencoded Payload Option
RFC8037: OKP Key and EdDSA algorithm
RFC8812: ES256K algorithm
RFC9278: JWK Thumbprint URI
RFC9864: Ed25519 and Ed448 algorithms
And draft RFCs implementation of:
draft-ietf-jose-deprecate-none-rsa15-02
draft-amringer-jose-chacha-02
draft-madden-jose-ecdh-1pu-04
Usage
A quick and simple JWT encoding and decoding would look something like this:
>>> from joserfc import jwt, jwk
>>> key = jwk.import_key("your-secret-key", "oct")
>>> encoded_jwt = jwt.encode({"alg": "HS256"}, {"k": "value"}, key)
>>> encoded_jwt
'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJrIjoidmFsdWUifQ._M8ViO_GK6TnZ9G9eqdlS7IpNWzhoGwaYYDQ3hEwwmA'
>>> token = jwt.decode(encoded_jwt, key)
>>> token.header
{'alg': 'HS256', 'typ': 'JWT'}
>>> token.claims
{'key': 'value'}
>>> claims_requests = jwt.JWTClaimsRegistry()
>>> claims_requests.validate(token.claims)
Useful Links
License
Licensed under BSD. Please see LICENSE for licensing details.
Metadata
Release files for joserfc 1.7.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| joserfc-1.7.5.tar.gz | 235.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| joserfc-1.7.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 306.3 kB
Release files / joserfc-1.7.5.tar.gz
| Download URL | joserfc-1.7.5.tar.gz |
|---|---|
| Size | 235.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d5ff536e658e17664f8c1b1ab60dc4aa62aa973fcef1edd33cc44bda45d6f5ea
|
|
BLAKE2b-256 checksum How to use checksums |
199480fea1514b7c6d7d37804d3fe9ca81455f633347fc98731bd71ffe1faa17
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 29, 2026.
Transparency logRelease files / joserfc-1.7.5-py3-none-any.whl
| Download URL | joserfc-1.7.5-py3-none-any.whl |
|---|---|
| Size | 71.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
add2c2c84e8373b084d526a8b53daba5d7a513a118cd2dcd9fc9f979d0922159
|
|
BLAKE2b-256 checksum How to use checksums |
67c582addfd375e5ee6520644e0553e4aadde92d668c4fc99cc716d337fe7bb3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 29, 2026.
Transparency log