jsonwt is a small, dependency-free Go package for issuing and consuming
signed, JWT-shaped tokens in local tools, demos, tests, and trusted internal
prototypes. It intentionally provides a narrow API and token format rather
than implementing the JWT standard.
Warning: Do not use
jsonwtfor production authentication, authorization, sessions, or across an untrusted network boundary. Tokens are signed but not encrypted, and the package does not provide key management, revocation, replay protection, or standards compatibility. Read Security and scope before choosing it.
In a Go module, run:
go get github.com/mdhender/jsonwt@latestThe module supports Go 1.17 and later.
Follow the tutorial and concise user manual to create an HS256 signer, issue a token with an application claim, parse and validate the token, and extract the claim.
- Tutorial and user manual
- How-to guides
- API reference
- Token format reference
- RFC 7519 differences and hypothetical compliance steps
- Security and design explanation
- Compatibility policy
- Changelog
- Contributing
- Release checklist
jsonwt is available under the MIT License.