Verifies JWT signatures against a JWKS endpoint, a PEM URL, a static key or (opt-in) a shared HMAC secret; enforces exp/nbf/iss/aud, scopes and optional jti replay protection; caches key material, handles key rotation, and exposes the verified claims to the application through the Rack environment. Pairs with the jwt_auth_client gem.

Required Ruby Version

>= 3.1

Authors

Daniele Frisanco

Versions

  1. 0.3.0 September 13, 2026 (31 KB)
  2. 0.2.0 September 12, 2026 (20.5 KB)
  3. 0.1.0 October 20, 2025 (12 KB)

SHA 256 checksum