All Projects → ethanhuang13 → Cupertinojwt

ethanhuang13 / Cupertinojwt

Licence: mit
Parse Apple's .p8 private key file and sign JWT with ES256, without third-party dependencies.

Programming Languages

swift
15916 projects

Labels

Projects that are alternatives of or similar to Cupertinojwt

Jwt
Kotlin JWT 🔑 implementation (Json Web Token) as required by APNs 🔔 (Apple Push Notifications) or Sign in with Apple 🍏
Stars: ✭ 31 (-71.03%)
Mutual labels:  apple, jwt
Apns2
⚡ HTTP/2 Apple Push Notification Service (APNs) push provider for Go — Send push notifications to iOS, tvOS, Safari and OSX apps, using the APNs HTTP/2 protocol.
Stars: ✭ 2,569 (+2300.93%)
Mutual labels:  apple, jwt
Typescript Restful Starter
Node.js + ExpressJS + Joi + Typeorm + Typescript + JWT + ES2015 + Clustering + Tslint + Mocha + Chai
Stars: ✭ 97 (-9.35%)
Mutual labels:  jwt
Express Jwt
An example API for creating/verifying json web tokens
Stars: ✭ 105 (-1.87%)
Mutual labels:  jwt
Hs Jose
Haskell JOSE and JWT library
Stars: ✭ 100 (-6.54%)
Mutual labels:  jwt
Ginbro
Converting a MySQL database'schema to a RESTful golang APIs app in the fastest way
Stars: ✭ 97 (-9.35%)
Mutual labels:  jwt
Kitsvc
⚙ 一個基於 Golang、Consul、Prometheus、EventStore、Gin、Gorm、NSQ 的微服務起始結構。
Stars: ✭ 101 (-5.61%)
Mutual labels:  jwt
Nginx Openid Connect
Reference implementation of OpenID Connect integration for NGINX Plus
Stars: ✭ 96 (-10.28%)
Mutual labels:  jwt
Zitadel
ZITADEL - Cloud Native Identity and Access Management
Stars: ✭ 105 (-1.87%)
Mutual labels:  jwt
Barong
Barong auth server
Stars: ✭ 100 (-6.54%)
Mutual labels:  jwt
Connectivity
🌐 Makes Internet connectivity detection more robust by detecting Wi-Fi networks without Internet access.
Stars: ✭ 1,476 (+1279.44%)
Mutual labels:  apple
Stompclientlib
Simple STOMP Client library, Swift 3 and 4, 4.2, 5 compatible
Stars: ✭ 99 (-7.48%)
Mutual labels:  apple
Insomnia
🌃 How to prevent screen lock on my application?
Stars: ✭ 98 (-8.41%)
Mutual labels:  apple
Fastsitephp
🌟 FastSitePHP 🌟 A Modern Open Source Framework for building High Performance Websites and API’s with PHP
Stars: ✭ 102 (-4.67%)
Mutual labels:  jwt
Micro Jwt Auth
jwt authorization wrapper for https://github.com/zeit/micro
Stars: ✭ 97 (-9.35%)
Mutual labels:  jwt
React Login
A client side implementation of authentication using react.js for my blog on medium. This is the second part of my previous blog on how to implement scalable node.js server.
Stars: ✭ 105 (-1.87%)
Mutual labels:  jwt
React Native Touch Id
React Native authentication with the native Touch ID popup.
Stars: ✭ 1,341 (+1153.27%)
Mutual labels:  apple
Django Auth0 Vue
A Django REST Framework + Vue.js CRUD Demo Secured Using Auth0
Stars: ✭ 99 (-7.48%)
Mutual labels:  jwt
Tailor
Cross-platform static analyzer and linter for Swift.
Stars: ✭ 1,370 (+1180.37%)
Mutual labels:  apple
Albookcode
Modern Auto Layout Book Sample Code And Solutions
Stars: ✭ 106 (-0.93%)
Mutual labels:  apple

CupertinoJWT

GitHub release GitHub top language License Twitter Donate

Parse Apple's .p8 private key file and sign JWT with ES256, without third-party dependencies. Supports Apple's server-side APIs.

Features

Features
😇 Open source iOS project written in Swift 4
Support iOS, macOS, tvOS, and watchOS
Parse Apple's .p8 private key file
Sign JSON Web Token with ES256 algorithm
Use Security and CommonCrypto only, no third-party dependencies
Support provider token based APNs connection
🏗 Support MusicKit
🏗 Support DeviceCheck
🏗 Support App Store Connect API

Install

CocoaPods

You can use CocoaPods to install CupertinoJWT by adding it to your Podfile:

platform :ios, '10.0'
use_frameworks!

target 'MyApp' do
    pod 'CupertinoJWT'
end

If you see CocoaPods warning about script phase, it is because CupertinoJWT requires CommonCrypto framework. And Apple didn't expose its header for Swift until Xcode 10. We use the script phase to generate module map to use it in Swift.

Carthage

Carthage is a simple, decentralized dependency manager for Cocoa. To install CupertinoJWT with Carthage:

  1. Make sure Carthage is installed.

  2. Update your Cartfile to include the following:

github "ethanhuang13/CupertinoJWT"
  1. Run carthage update and add the appropriate framework.

What's this all about?

Apple has several server APIs uses JSON Web Token(JWT) as authentication method, including Apple Push Notification service (APNs), MusicKit, DeviceCheck and App Store Connect API. Probably more in the future.

After creating the token, one must sign it with an Apple-provided private key, using the Elliptic Curve Digital Signature Algorithm (ECDSA) with the P-256 curve and the SHA-256 hash algorithm, or ES256.

This task is very common and well-supported with mature server-side languages like Ruby, Java, Python, or JS. With Swift, however, is not that easy. One often needs to use OpenSSL or its forks, even server-side Swift frameworks like Vapor or Perfect use OpenSSL forks. If you want to do this on iOS, it's even harder.

Personally I'm interested in creating developer tools running on iOS. For example, we can use the JWT for App Store Connect API on a developer tool app.

Turned out we can just use Apple's Security and CommonCrypto frameworks, and support all Apple platforms. And that's what CupertinoJWT does.

The result is, with CupertinoJWT, we can easily create developer tools on iOS (and also macOS, tvOS, and watchOS) connecting to APNs, App Store Connect, or other Apple server APIs.

What does CupertinoJWT do?

The private keys provided by Apple are PEM format .p8 files. CupertinoJWT parses and convert them to ASN.1 data, retrieve the private keys, loads with SecKeyCreateWithData method, and finally create signature using SecKeyCreateSignature method.

Usage

First, get your .p8 key file from Apple Developer site. It can be download once. Keep the file safe. (As a developer, you should know the importance for keeping the private keys safe.)

Then, follow the sample code below:

// Get content of the .p8 file
let p8 = """
-----BEGIN PRIVATE KEY-----
MIGTAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBHkwdwIBAQQgGH2MylyZjjRdauTk
xxXW6p8VSHqIeVRRKSJPg1xn6+KgCgYIKoZIzj0DAQehRANCAAS/mNzQ7aBbIBr3
DiHiJGIDEzi6+q3mmyhH6ZWQWFdFei2qgdyM1V6qtRPVq+yHBNSBebbR4noE/IYO
hMdWYrKn
-----END PRIVATE KEY-----
"""

// Assign developer information and token expiration setting
let jwt = JWT(keyID: keyID, teamID: teamID, issueDate: Date(), expireDuration: 60 * 60)

do {
    let token = try jwt.sign(with: p8)
    // Use the token in the authorization header in your requests connecting to Apple’s API server.
    // e.g. urlRequest.addValue(_ value: "bearer \(token)", forHTTPHeaderField field: "authorization")
} catch {
    // Handle error
}

Contribution

  • Feedback and issues are welcome.
  • Submit each pull request for single purpose. Here is a great article about making code review easier.

Special Thanks

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].