Verifies JWT signatures against a JWKS endpoint, a PEM URL, a static key or (opt-in) a shared HMAC secret; enforces exp/nbf/iss/aud, scopes and optional jti replay protection; caches key material, handles key rotation, and exposes the verified claims to the application through the Rack environment. Pairs with the jwt_auth_client gem.

Required Ruby Version

>= 3.1

Authors

Daniele Frisanco

Versions

  1. 0.3.0
    1. source

      1. 0.3.0 source September 13, 2026 (31 KB)
  2. 0.2.0
    1. source

      1. 0.2.0 source September 12, 2026 (20.5 KB)
  3. 0.1.0
    1. source

      1. 0.1.0 source October 20, 2025 (12 KB)

SHA 256 checksum