Paseto is your favorite for JOSE (JWT, JWE, JWS) without any of the design flaws that plague the JOSE standard.
PASETO implementation
v3/v4 support
Name | Language | Author | Features | v3.l | v3.p | Convert key | ROUTE PASERK |
---|---|---|---|
go |
)
Python | Daisuke Aichi | |
---|
v1/v2 support
Name | language | author | Features | v1.l | v1.p | v2.l | v2.p | |||
---|---|---|---|---|---|---|---|---|---|---|
C | Thomas Reynolds |
Ian Clark |
| |
|
|
| go |
Aidan T. Woods |
|
|
| |
Oleg Vakarev
nbaars/paseto4j Java
brycx/pasetors rust
Conference presentations and presentations
Slideshow (LibreOffice) Slides (PDF) Video (YouTube)
Vulnerability research and cryptanalysis over the past three years on the JOSE family of internet standards (most commonly known as JSON Web Tokens aka JWT). This has led many security experts to boldly declare: “Don’t use JWTs!” but left many developers without viable alternatives. Scott went a step further and devised a more secure alternative: PASETO (Platform Independent Security Token), currently implemented in 10 programming languages.
project status
Available Documents
Protocol Definition
Implementer’s Guide
exist Implementations in multiple programming languages and environments
This site is open source
on
Github.
This site is open source