← All @molecule/* packages · App templates

@molecule/api-jwt-jsonwebtoken

Provider bond · jwt · API (Node) · v1.0.1 · Apache-2.0

JWT provider using jsonwebtoken for molecule.dev

npm install @molecule/api-jwt-jsonwebtoken

npm · Source on GitHub · Implements @molecule/api-jwt

How it works

@molecule/api-jwt-jsonwebtoken is a provider bond on the API (Node) side: it implements the jwt core interface (@molecule/api-jwt) with a concrete vendor or library behind it.

Your code calls the core; you wire this provider once at startup. Swapping vendors later is one line in that wiring, not a rewrite.

import { setProvider } from '@molecule/api-jwt'
import { provider } from '@molecule/api-jwt-jsonwebtoken'

setProvider(provider)

Works with: @molecule/api-jwt, @molecule/api-secrets

Secrets: JWT_PRIVATE_KEY, JWT_PUBLIC_KEY

Reference

Auto-generated, AI-first package reference for the molecule.dev ecosystem. It is written to be read by coding agents as much as by people, and is generated from this package's source — edit src/index.ts JSDoc, not this file.

JSON Web Token provider using jsonwebtoken for molecule.dev.

Implements the @molecule/api-jwt JwtProvider contract (sign, verify, decode) as a thin wrapper over the jsonwebtoken library. Key sourcing, algorithms, and usage rules live in @molecule/api-jwt — its convenience functions supply JWT_PRIVATE_KEY/JWT_PUBLIC_KEY (env-provided or self-generated) automatically.

Quick Start

import { setProvider } from '@molecule/api-jwt'
import { provider } from '@molecule/api-jwt-jsonwebtoken'

setProvider(provider)

Type

provider

Installation

npm install @molecule/api-jwt-jsonwebtoken @molecule/api-jwt @molecule/api-secrets jsonwebtoken
npm install -D @types/jsonwebtoken

API

Constants

jwtJsonwebtokenSecretDefinitions

Secret definitions required by the jsonwebtoken JWT bond.

const jwtJsonwebtokenSecretDefinitions: SecretDefinition[]

provider

JWT provider backed by the jsonwebtoken library.

const provider: JwtProvider

Core Interface

Implements @molecule/api-jwt interface.

Bond Wiring

Setup function to register this provider with the core interface:

import { setProvider } from '@molecule/api-jwt'
import { provider } from '@molecule/api-jwt-jsonwebtoken'

export function setupJwtJsonwebtoken(): void {
  setProvider(provider)
}

Injection Notes

Requirements

Peer dependencies:

  • @molecule/api-jwt ^1.0.1
  • @molecule/api-secrets ^1.0.1

Environment Variables

  • JWT_PRIVATE_KEY (required) — JWT signing key (RSA private)
    • Auto-generated at scaffold — no manual setup.
  • JWT_PUBLIC_KEY (required) — JWT verification key (RSA public)
    • Auto-generated at scaffold — no manual setup.

Runtime Dependencies

  • @molecule/api-jwt

  • @molecule/api-secrets

  • jsonwebtoken

  • verify() force-enables expiry and not-before checks — any ignoreExpiration/ignoreNotBefore passed in options is overridden (deliberate hardening: an expired token ALWAYS fails). Don't build accept-expired-token flows on this bond; issue short-lived tokens and refresh instead (see the core's refresh recipe).

  • Provider-level sign/verify throw if called without a key argument; the core's convenience wrappers inject the keys — call those, not the provider methods, unless you are supplying custom keys.