← All @molecule/* packages · App templates
@molecule/api-jwt-jsonwebtokenProvider bond · jwt · API (Node) · v1.0.1 · Apache-2.0
JWT provider using jsonwebtoken for molecule.dev
npm install @molecule/api-jwt-jsonwebtokennpm · Source on GitHub · Implements @molecule/api-jwt
@molecule/api-jwt-jsonwebtoken is a provider bond on the API (Node) side: it implements the jwt core interface (@molecule/api-jwt) with a concrete vendor or library behind it.
Your code calls the core; you wire this provider once at startup. Swapping vendors later is one line in that wiring, not a rewrite.
import { setProvider } from '@molecule/api-jwt'
import { provider } from '@molecule/api-jwt-jsonwebtoken'
setProvider(provider)Works with: @molecule/api-jwt, @molecule/api-secrets
Secrets: JWT_PRIVATE_KEY, JWT_PUBLIC_KEY
Auto-generated, AI-first package reference for the molecule.dev ecosystem. It is written to be read by coding agents as much as by people, and is generated from this package's source — edit
src/index.tsJSDoc, not this file.
JSON Web Token provider using jsonwebtoken for molecule.dev.
Implements the @molecule/api-jwt JwtProvider contract (sign,
verify, decode) as a thin wrapper over the jsonwebtoken library.
Key sourcing, algorithms, and usage rules live in @molecule/api-jwt —
its convenience functions supply JWT_PRIVATE_KEY/JWT_PUBLIC_KEY
(env-provided or self-generated) automatically.
import { setProvider } from '@molecule/api-jwt'
import { provider } from '@molecule/api-jwt-jsonwebtoken'
setProvider(provider)
provider
npm install @molecule/api-jwt-jsonwebtoken @molecule/api-jwt @molecule/api-secrets jsonwebtoken
npm install -D @types/jsonwebtoken
jwtJsonwebtokenSecretDefinitionsSecret definitions required by the jsonwebtoken JWT bond.
const jwtJsonwebtokenSecretDefinitions: SecretDefinition[]
providerJWT provider backed by the jsonwebtoken library.
const provider: JwtProvider
Implements @molecule/api-jwt interface.
Setup function to register this provider with the core interface:
import { setProvider } from '@molecule/api-jwt'
import { provider } from '@molecule/api-jwt-jsonwebtoken'
export function setupJwtJsonwebtoken(): void {
setProvider(provider)
}
Peer dependencies:
@molecule/api-jwt ^1.0.1@molecule/api-secrets ^1.0.1JWT_PRIVATE_KEY (required) — JWT signing key (RSA private)
JWT_PUBLIC_KEY (required) — JWT verification key (RSA public)
@molecule/api-jwt
@molecule/api-secrets
jsonwebtoken
verify() force-enables expiry and not-before checks — any
ignoreExpiration/ignoreNotBefore passed in options is overridden
(deliberate hardening: an expired token ALWAYS fails). Don't build
accept-expired-token flows on this bond; issue short-lived tokens and
refresh instead (see the core's refresh recipe).
Provider-level sign/verify throw if called without a key argument;
the core's convenience wrappers inject the keys — call those, not the
provider methods, unless you are supplying custom keys.