JWT Based Authentication
Overview
This guide explains how to authenticate Signzy API requests using JWT-based access tokens. You will be provided with a key (iss) and secret to generate a JWT token.
Signzy APIs use JWT tokens for authentication. Each client is required to generate a signed JWT token and include it in the Authorization header of their requests.
Prerequisites
You need the key (iss) and secret provided by us.
A library to generate JWT tokens (e.g., jsonwebtoken for Node.js, jwt for Python, etc.).
Token Requirements
Payload Fields
iss: Use the provided key as the issuer.
exp: Set an expiration time, in seconds since the Unix epoch. This value must not be greater than a day.
Algorithm
Use HS256 for signing the JWT.
Generating a JWT Token
Below are examples of how to generate a JWT token in different programming languages:
import com.auth0.jwt.JWT;
import com.auth0.jwt.algorithms.Algorithm;
import java.util.Date;
public class JWTGenerator {
public static void main(String[] args) {
String key = "your-issuer-key"; // Replace with your actual key
String secret = "your-secret-key"; // Replace with your actual secret
Algorithm algorithm = Algorithm.HMAC256(secret);
String token = JWT.create()
.withIssuer(key)
.withExpiresAt(new Date(System.currentTimeMillis() + 3600 * 1000)) // Expires in 1 hour
.sign(algorithm);
System.out.println("Generated JWT Token: " + token);
}
}Note: Users can add custom key in JWT payload to make the token unique.
Using the JWT Token
Once you have generated the token, include it in the Authorization header of your HTTP requests
Example
curl -X GET "https: /api.signzy.com/your-endpoint" \
-H "Authorization: Bearer <your-jwt-token>" \
-H "Content-Type: application/json" Token Expiration
The token's exp field specifies the expiration time.
Ensure the expiry is less than a day.