cwt library
CBOR Web Tokens on top of COSE Sign1.
https://datatracker.ietf.org/doc/html/rfc8392
Tokens carry a set of Claims encoded as a CBOR map. Standard CWT and EAT
claims have typed accessors; custom claims use integer keys via
operator[].
verify checks the signature against the supplied key and, when requested,
the nbf and exp time bounds. Applications must establish trust in that
key, check issuer and audience claims, and apply their own attestation
policy. EAT claim relationships and proof of possession of a cnf key are
not automatically checked.
Example
import 'dart:convert';
import 'package:darkbio_crypto/cwt.dart' as cwt;
import 'package:darkbio_crypto/xdsa.dart' as xdsa;
void example() {
final issuer = xdsa.SecretKey.generate();
final device = xdsa.SecretKey.generate();
final domain = utf8.encode('device-cert');
const now = 1700000000;
final claims = cwt.Claims()
..subject = 'ark-0001'
..expiration = now + 3600
..notBefore = now
..setConfirmXdsa(device.publicKey());
final token = cwt.issue(claims: claims, signer: issuer, domain: domain);
final verified = cwt.verify(token: token, verifier: issuer.publicKey(), domain: domain, now: now + 60);
assert(verified.subject == 'ark-0001');
}
Classes
- Claims
- A CWT claims set with typed accessors for standard CWT (RFC 8392) and EAT (RFC 9711) claims.
Enums
- DebugState
- Debug port state per RFC 9711 Section 4.2.9.
- IntendedUse
- Token intended purpose per RFC 9711 Section 4.3.3.
Functions
-
issue(
{required Claims claims, required SecretKey signer, required Uint8List domain}) → Uint8List -
Issues a CWT by signing the
claimswith COSE Sign1. -
peek(
{required Uint8List token}) → Claims - Extracts claims from a CWT without verifying the signature.
-
signer(
{required Uint8List token}) → Fingerprint - Extracts the signer's fingerprint from a CWT without verifying.
-
verify(
{required Uint8List token, required PublicKey verifier, required Uint8List domain, int? now}) → Claims - Verifies a CWT's COSE signature and temporal validity, then returns the decoded claims.