cwt library

CBOR Web Tokens on top of COSE Sign1.

https://datatracker.ietf.org/doc/html/rfc8392

Tokens carry a set of Claims encoded as a CBOR map. Standard CWT and EAT claims have typed accessors; custom claims use integer keys via operator[].

verify checks the signature against the supplied key and, when requested, the nbf and exp time bounds. Applications must establish trust in that key, check issuer and audience claims, and apply their own attestation policy. EAT claim relationships and proof of possession of a cnf key are not automatically checked.

Example

import 'dart:convert';

import 'package:darkbio_crypto/cwt.dart' as cwt;
import 'package:darkbio_crypto/xdsa.dart' as xdsa;

void example() {
  final issuer = xdsa.SecretKey.generate();
  final device = xdsa.SecretKey.generate();
  final domain = utf8.encode('device-cert');
  const now = 1700000000;

  final claims = cwt.Claims()
    ..subject = 'ark-0001'
    ..expiration = now + 3600
    ..notBefore = now
    ..setConfirmXdsa(device.publicKey());
  final token = cwt.issue(claims: claims, signer: issuer, domain: domain);

  final verified = cwt.verify(token: token, verifier: issuer.publicKey(), domain: domain, now: now + 60);
  assert(verified.subject == 'ark-0001');
}

Classes

Claims
A CWT claims set with typed accessors for standard CWT (RFC 8392) and EAT (RFC 9711) claims.

Enums

DebugState
Debug port state per RFC 9711 Section 4.2.9.
IntendedUse
Token intended purpose per RFC 9711 Section 4.3.3.

Functions

issue({required Claims claims, required SecretKey signer, required Uint8List domain}) → Uint8List
Issues a CWT by signing the claims with COSE Sign1.
peek({required Uint8List token}) → Claims
Extracts claims from a CWT without verifying the signature.
signer({required Uint8List token}) → Fingerprint
Extracts the signer's fingerprint from a CWT without verifying.
verify({required Uint8List token, required PublicKey verifier, required Uint8List domain, int? now}) → Claims
Verifies a CWT's COSE signature and temporal validity, then returns the decoded claims.