@edgetoken/core
    Preparing search index...

    Function verifyJwt

    • Verifies a compact JWT's HMAC signature, expiration, and claim constraints.

      Enforces strict algorithm validation to prevent algorithm confusion attacks (such as rejecting the unsigned none algorithm).

      Type Parameters

      • T = Record<string, unknown>

        The expected shape of the claims payload.

      Parameters

      • token: string

        The serialized compact JWT (header.payload.signature).

      • secret: string | Uint8Array<ArrayBufferLike>

        The shared symmetric key matching the one used to sign the token.

      • options: JwtVerifyOptions = {}

        Validation constraints for issuer and audience.

      Returns Promise<T>

      A Promise resolving to the typed claims payload.

      If the token structure is malformed.

      If the algorithm is unsupported or insecure.

      If the HMAC signature is invalid.

      If the token is expired (exp) or not yet active (nbf).

      If issuer or audience constraints fail.

      try {
      const claims = await verifyJwt<{ sub: string }>(token, "my-super-secret-key");
      console.log("Authenticated user:", claims.sub);
      } catch (err) {
      console.error("JWT verification failed:", err.message);
      }