Skip to main content

USSO-JWT

A secure and flexible JWT (JSON Web Token) implementation for Python, designed to work seamlessly with the USSO authentication system. This library provides a robust set of tools for creating, signing, verifying, and managing JWTs with support for multiple cryptographic algorithms.

Features

  • Multiple Algorithm Support:

    • HMAC (HS256, HS384, HS512)
    • RSA (RS256, RS384, RS512, PS256, PS384, PS512)
    • ECDSA (ES256, ES384, ES512)
    • EdDSA (Ed25519)
  • JWK Support: Full support for JSON Web Keys (JWK) format

  • PEM Support: Load keys from PEM-encoded files

  • Type Safety: Built with type hints for better IDE support and code safety

  • Comprehensive Testing: Thorough test coverage for all algorithms and features

Installation

Install using pip:

pip install usso-jwt

Quick Start

Creating and Signing a JWT

from usso_jwt import JWT

# Create a JWT with a payload
jwt = JWT(payload={"sub": "1234567890", "name": "John Doe", "iat": 1516239022})

# Sign with HMAC
token = jwt.sign(hmac_key, "HS256")

# Sign with RSA
token = jwt.sign(rsa_private_key, "RS256")

# Sign with ECDSA
token = jwt.sign(ecdsa_private_key, "ES256")

# Sign with EdDSA
token = jwt.sign(eddsa_private_key, "Ed25519")

Verifying a JWT

from usso_jwt import JWT

# Verify with HMAC
jwt = JWT.verify(token, hmac_key, "HS256")

# Verify with RSA
jwt = JWT.verify(token, rsa_public_key, "RS256")

# Verify with ECDSA
jwt = JWT.verify(token, ecdsa_public_key, "ES256")

# Verify with EdDSA
jwt = JWT.verify(token, eddsa_public_key, "Ed25519")

Working with JWKs

from usso_jwt import JWT

# Create a JWT with a JWK
jwt = JWT(payload={"sub": "1234567890"})

# Sign with a JWK
token = jwt.sign(jwk, "RS256")

# Verify with a JWK
jwt = JWT.verify(token, jwk, "RS256")

Supported Algorithms

HMAC (Symmetric)

  • HS256: HMAC with SHA-256
  • HS384: HMAC with SHA-384
  • HS512: HMAC with SHA-512

RSA (Asymmetric)

  • RS256: RSA with SHA-256
  • RS384: RSA with SHA-384
  • RS512: RSA with SHA-512
  • PS256: RSA-PSS with SHA-256
  • PS384: RSA-PSS with SHA-384
  • PS512: RSA-PSS with SHA-512

ECDSA (Asymmetric)

  • ES256: ECDSA with P-256 and SHA-256
  • ES384: ECDSA with P-384 and SHA-384
  • ES512: ECDSA with P-521 and SHA-512

EdDSA (Asymmetric)

  • EdDSA: Ed25519

Security Considerations

  • Always use strong keys appropriate for your chosen algorithm
  • For HMAC, use keys at least as long as the hash output (e.g., 32 bytes for HS256)
  • For RSA, use keys of at least 2048 bits
  • For ECDSA, use the recommended curves (P-256, P-384, P-521)
  • Store private keys securely and never expose them
  • Use appropriate key rotation policies

Contributing

Contributions are welcome! Please feel free to submit a Pull Request. For major changes, please open an issue first to discuss what you would like to change.

License

This project is licensed under the MIT License - see the LICENSE file for details.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

usso_jwt-0.2.16.tar.gz (26.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

usso_jwt-0.2.16-py3-none-any.whl (26.3 kB view details)

Uploaded Python 3

File details

Details for the file usso_jwt-0.2.16.tar.gz.

File metadata

  • Download URL: usso_jwt-0.2.16.tar.gz
  • Upload date:
  • Size: 26.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for usso_jwt-0.2.16.tar.gz
Algorithm Hash digest
SHA256 2723f5e7d46a57f10a96f4da999b1f25f896ff4ca0fa7d33d1b6f3ea04e89d00
MD5 ab74d1965d18fc62c9cf937a41f238d5
BLAKE2b-256 9e4c0be1ce9ac2d93cdc00d37a3bd28d2b0cedf46dfdcd3dca7a4c9316bccd78

See more details on using hashes here.

File details

Details for the file usso_jwt-0.2.16-py3-none-any.whl.

File metadata

  • Download URL: usso_jwt-0.2.16-py3-none-any.whl
  • Upload date:
  • Size: 26.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for usso_jwt-0.2.16-py3-none-any.whl
Algorithm Hash digest
SHA256 dc90121aef4ce8a3d16166d02d4d892d0e5a4ab72659bfb95af927366212c9dd
MD5 d02f3a2a04c0058706cb1fb49274d91b
BLAKE2b-256 41024be55437d419b7388343c573a0375ec1dd4ace09a6556290d4a4c6078739

See more details on using hashes here.

Release history Release notifications | RSS feed

0.2.18

2 files

0.2.17

2 files

This release

0.2.16 This release

2 files

0.2.10

2 files

0.2.9

2 files

0.2.6

2 files

0.2.4

2 files

0.2.3

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

0.1.19

2 files

0.1.18

2 files

0.1.17

2 files

0.1.16

2 files

0.1.15

2 files

0.1.14

2 files

0.1.13

2 files

0.1.12

2 files

0.1.11

2 files

0.1.10

2 files

0.1.9

2 files

0.1.8

2 files

0.1.7

2 files

0.1.6

2 files

0.1.5

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page