JWT
Type ID: core.jwt · Kind: Action · Ports: 1 in, 1 out
Signs a payload into a JWT or verifies an existing token, in both cases using the HS256 algorithm and a shared secret. Optional issuer and audience claims can be included when signing or validated when verifying.
Credentials
None
Properties
| Property | Key | Type | Required | Default | Possible values | Applies when |
|---|---|---|---|---|---|---|
| Operation | operation | options | Yes | sign | sign - Sign; verify - Verify | Always |
| Payload | payload | object | No | {} | an object to sign | operation = sign |
| Token | token | string | No | '' | the JWT token to verify | operation = verify |
| Secret | secret | string | Yes | '' | the shared secret used for HS256 signing and verification | Always |
| Expires In | expiresIn | string | No | '' | optional token lifetime such as 5m or 1h (also accepts a numeric seconds value) | operation = sign |
| Issuer | issuer | string | No | '' | optional issuer claim to include or validate | Always |
| Audience | audience | string | No | '' | optional audience claim to include or validate | Always |
Notes
secretis required and must be a non-empty string, otherwise execution throws.- Sign:
payloadmust be a plain object. Output:{ token }. - Verify:
tokenis required; an invalid token throws. Output:{ valid: true, payload }(a string-decoded payload is wrapped as{ value: <string> }).