Local JWT decoding and asymmetric signature verification for Supabase Auth.
Supabase issues JWTs signed with either a symmetric secret (HS256, the
legacy default — not verifiable client-side) or an asymmetric key
(RS256 / ES256). For asymmetric algorithms the public keys are
published at <auth-url>/.well-known/jwks.json; on the JVM this
namespace fetches and caches that JWKS and verifies signatures using the
JDK's built-in crypto, with no third-party dependency.
ClojureScript gets decode only: signature verification stays on the
JVM (or server-side via supabase.auth/get-user), since fetching and
caching JWKS is an async operation on that platform.
Callers should use supabase.auth/get-claims rather than these helpers
directly.
Local JWT decoding and asymmetric signature verification for Supabase Auth. Supabase issues JWTs signed with either a symmetric secret (`HS256`, the legacy default — not verifiable client-side) or an asymmetric key (`RS256` / `ES256`). For asymmetric algorithms the public keys are published at `<auth-url>/.well-known/jwks.json`; on the JVM this namespace fetches and caches that JWKS and verifies signatures using the JDK's built-in crypto, with no third-party dependency. ClojureScript gets [[decode]] only: signature verification stays on the JVM (or server-side via `supabase.auth/get-user`), since fetching and caching JWKS is an async operation on that platform. Callers should use [[supabase.auth/get-claims]] rather than these helpers directly.
(clear-cache!)Clears the process-global JWKS cache. Primarily for tests. JVM only.
Clears the process-global JWKS cache. Primarily for tests. JVM only.
(decode token)Splits and decodes a JWT into {:header :payload :signed-data :signature}
without verifying it. Returns an anomaly if the token is malformed.
On ClojureScript :signed-data is the raw header.payload string and
:signature is the undecoded base64url segment; neither is used on that
platform (verification is JVM-only).
Splits and decodes a JWT into `{:header :payload :signed-data :signature}`
without verifying it. Returns an anomaly if the token is malformed.
On ClojureScript `:signed-data` is the raw `header.payload` string and
`:signature` is the undecoded base64url segment; neither is used on that
platform (verification is JVM-only).(verify auth-url token)Verifies token against the JWKS published at auth-url and returns
{:claims <payload> :header <header>} on success, or an anomaly.
JVM only.
Only asymmetric algorithms (RS256, ES256) are verified here; callers
fall back to server-side verification for HS256.
Verifies `token` against the JWKS published at `auth-url` and returns
`{:claims <payload> :header <header>}` on success, or an anomaly.
JVM only.
Only asymmetric algorithms (`RS256`, `ES256`) are verified here; callers
fall back to server-side verification for `HS256`.(verify-with-keys jwks token)Like verify, but verifies against an already-resolved JWKS keys
vector instead of fetching one. Network-free. JVM only.
Like [[verify]], but verifies against an already-resolved JWKS `keys` vector instead of fetching one. Network-free. JVM only.
cljdoc builds & hosts documentation for Clojure/Script libraries
| Ctrl+k | Jump to recent docs |
| ← | Move to previous article |
| → | Move to next article |
| Ctrl+/ | Jump to the search field |