pub struct JwtService { /* private fields */ }Expand description
JWT service with key rotation and multi-algorithm support
Maintains an active signing key and a list of retired keys. Tokens are always signed with the active key. Validation tries the active key first, then retired keys within the grace period.
Supports both HS256 (shared secret) and RS256 (RSA key pair).
Implementations§
Source§impl JwtService
impl JwtService
Sourcepub fn with_rotation(secret: &str, config: KeyRotationConfig) -> Self
pub fn with_rotation(secret: &str, config: KeyRotationConfig) -> Self
Create a new JWT service with HS256 and explicit rotation configuration
Sourcepub fn new_rs256(private_key_pem: &str, public_key_pem: &str) -> Result<Self>
pub fn new_rs256(private_key_pem: &str, public_key_pem: &str) -> Result<Self>
Create a new JWT service with RS256 (asymmetric)
Validates the RSA key pair on construction — returns an error if the keys are malformed or cannot be used for signing/verification.
Sourcepub fn with_rs256_rotation(
private_key_pem: &str,
public_key_pem: &str,
config: KeyRotationConfig,
) -> Result<Self>
pub fn with_rs256_rotation( private_key_pem: &str, public_key_pem: &str, config: KeyRotationConfig, ) -> Result<Self>
Create a new JWT service with RS256 and explicit rotation configuration
Validates the RSA key pair on construction — returns an error if the keys are malformed or cannot be used for signing/verification.
Sourcepub fn active_kid(&self) -> String
pub fn active_kid(&self) -> String
Get the current active key ID
Sourcepub fn algorithm(&self) -> JwtAlgorithm
pub fn algorithm(&self) -> JwtAlgorithm
Get the algorithm used by this service
Sourcepub fn public_key_pem(&self) -> Option<String>
pub fn public_key_pem(&self) -> Option<String>
Export the public key PEM (RS256 only, returns None for HS256)
Sourcepub fn rotate_key(&self, new_secret: &str) -> Result<String>
pub fn rotate_key(&self, new_secret: &str) -> Result<String>
Rotate the HS256 signing key.
Returns the kid of the new active key.
Sourcepub fn rotate_rsa_key(
&self,
private_key_pem: &str,
public_key_pem: &str,
) -> Result<String>
pub fn rotate_rsa_key( &self, private_key_pem: &str, public_key_pem: &str, ) -> Result<String>
Rotate the RS256 key pair.
Validates the new key pair before rotating. Returns the kid of the new active key.
Sourcepub fn create_token(&self, claims: &Claims) -> Result<String>
pub fn create_token(&self, claims: &Claims) -> Result<String>
Create JWT token (signs with the active key, includes kid in header)
Sourcepub fn create_refresh_token(
&self,
claims: &RefreshTokenClaims,
) -> Result<String>
pub fn create_refresh_token( &self, claims: &RefreshTokenClaims, ) -> Result<String>
Create refresh token (signs with the active key)
Sourcepub fn validate_token(&self, token: &str) -> Result<Claims>
pub fn validate_token(&self, token: &str) -> Result<Claims>
Validate JWT token (tries active key first, then retired keys)
Sourcepub fn decode_token(&self, token: &str) -> Result<Claims>
pub fn decode_token(&self, token: &str) -> Result<Claims>
Decode JWT token without expiration validation
Sourcepub fn validate_refresh_token(&self, token: &str) -> Result<RefreshTokenClaims>
pub fn validate_refresh_token(&self, token: &str) -> Result<RefreshTokenClaims>
Validate refresh token (tries all valid keys)