This repository is an open-source Java library for fast and convenient using of JWT tokens in your Java applications.
At first, you need to install this library.
With Maven add dependency to your pom.xml
This library provides simple and convenient usage.
You need to create TokenService
object and pass secret
(base64 encoded secret string for JWT tokens)
to the constructor.
public class Main {
public static void main(String[] args) {
String secret = "aGZiYmtiYWllYmNpZWFpZWJsZWNldWNlY2xhZWNhaWJlbGNhZWN3Q0VCV0VXSUM=";
TokenService tokenService = new TokenServiceImpl(secret);
After, you can call available methods and use library.
Library supports PersistentTokenService
implementation with saving tokens to TokenStorage
With such approach you can store tokens in Redis or in-memory Map and create new one if no specified tokens exist, otherwise, stored JWT token would be returned.
This approach allows you to invalidate created and stored JWT token.
For this look at TokenStorage
class. Use TokenStorageImpl
for in-memory storage (default)
and RedisTokenStorageImpl
for Redis storage.
public class Main {
public static void main(String[] args) {
String secret = "aGZiYmtiYWllYmNpZWFpZWJsZWNldWNlY2xhZWNhaWJlbGNhZWN3Q0VCV0VXSUM=";
TokenService tokenService = new PersistentTokenServiceImpl(secret);
With Redis you need to pass RedisTokenStorageImpl
object to constructor.
To create RedisTokenStorageImpl
you need to pass JedisPool
/ host and port / host, port, username and password.
public class Main {
public static void main(String[] args) {
String secret = "aGZiYmtiYWllYmNpZWFpZWJsZWNldWNlY2xhZWNhaWJlbGNhZWN3Q0VCV0VXSUM=";
String host = "localhost";
int port = 6379;
TokenStorage tokenStorage = new RedisTokenStorageImpl(host, port);
PersistentTokenService tokenService = new PersistentTokenServiceImpl(secret, tokenStorage);
You can choose your own RedisSchema
which is used to generate a Redis key for JWT token.
Just pass it as argument in RedisTokenStorageImpl
By default, library uses key "tokens:" + subject + ":" + type
With PersistentTokenService
you can invalidate token by token itself or by subject and token type.
If first option is chosen, all keys with such token values will be deleted.
If token will be deleted from storage you receive true
public class Main {
public static void main(String[] args) {
String token = "eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJhbmRyb3Nvcjk5QGdtYWlsLmNvbSIsImlkIjozLCJyb2xlcyI6WyJST0xFX1VTRVIiXSwiZXhwIjoxNzE3MTQ1MDIxfQ.w8ZFLFsKf7Qs9_dNb0WzdoyAIpWtfeEyqLfNI_G16_6NHbGwCRbeVVm_a_DzckytsyGYHTWRlZdi_gWK-HjrXg";
boolean deleted = persistentTokenService.invalidate(token);
public class Main {
public static void main(String[] args) {
boolean deleted = persistentTokenService.invalidate(
Duration.of(1, ChronoUnit.HOURS)
To create token call method create(TokenParameters params)
on TokenService
public class Main {
public static void main(String[] args) {
String token = tokenService.create(
TokenParameters.builder("", "access", Duration.of(1, ChronoUnit.HOURS))
You can specify in TokenParameters
- claims to be put in JWT token
- JWT token issuing date
- JWT token expiration date
- "sub" of JWT token
- type of JWT token
This all is configured via TokenParameters
To check if JWT token is expired call method isExpired(String token)
on TokenService
class Main {
public static void main(String[] args) {
String token = "eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJhbmRyb3Nvcjk5QGdtYWlsLmNvbSIsImlkIjozLCJyb2xlcyI6WyJST0xFX1VTRVIiXSwiZXhwIjoxNzE3MTQ1MDIxfQ.w8ZFLFsKf7Qs9_dNb0WzdoyAIpWtfeEyqLfNI_G16_6NHbGwCRbeVVm_a_DzckytsyGYHTWRlZdi_gWK-HjrXg";
boolean expired = tokenService.isExpired(token);
You can also check expiration with any other date.
class Main {
public static void main(String[] args) {
String token = "eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJhbmRyb3Nvcjk5QGdtYWlsLmNvbSIsImlkIjozLCJyb2xlcyI6WyJST0xFX1VTRVIiXSwiZXhwIjoxNzE3MTQ1MDIxfQ.w8ZFLFsKf7Qs9_dNb0WzdoyAIpWtfeEyqLfNI_G16_6NHbGwCRbeVVm_a_DzckytsyGYHTWRlZdi_gWK-HjrXg";
Date date = new Date(1705911211182);
boolean expired = tokenService.isExpired(token, date);
To check if JWT token has claim in payload call method has(String token, String key, Object value)
on TokenService
class Main {
public static void main(String[] args) {
String token = "eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJhbmRyb3Nvcjk5QGdtYWlsLmNvbSIsImlkIjozLCJyb2xlcyI6WyJST0xFX1VTRVIiXSwiZXhwIjoxNzE3MTQ1MDIxfQ.w8ZFLFsKf7Qs9_dNb0WzdoyAIpWtfeEyqLfNI_G16_6NHbGwCRbeVVm_a_DzckytsyGYHTWRlZdi_gWK-HjrXg";
String key = "subject";
String value = "1234567890";
boolean hasSubject = tokenService.has(token, key, value);
To get subject from JWT token payload call method getSubject(String token)
on TokenService
Note: Optionally, you can call
method claims(token).get("sub").toString()
on TokenService
public class Main {
public static void main(String[] args) {
String token = "eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJhbmRyb3Nvcjk5QGdtYWlsLmNvbSIsImlkIjozLCJyb2xlcyI6WyJST0xFX1VTRVIiXSwiZXhwIjoxNzE3MTQ1MDIxfQ.w8ZFLFsKf7Qs9_dNb0WzdoyAIpWtfeEyqLfNI_G16_6NHbGwCRbeVVm_a_DzckytsyGYHTWRlZdi_gWK-HjrXg";
String subject = tokenService.getSubject(token);
To get type from JWT token payload call method getType(String token)
on TokenService
public class Main {
public static void main(String[] args) {
String token = "eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJhbmRyb3Nvcjk5QGdtYWlsLmNvbSIsImlkIjozLCJyb2xlcyI6WyJST0xFX1VTRVIiXSwiZXhwIjoxNzE3MTQ1MDIxfQ.w8ZFLFsKf7Qs9_dNb0WzdoyAIpWtfeEyqLfNI_G16_6NHbGwCRbeVVm_a_DzckytsyGYHTWRlZdi_gWK-HjrXg";
String subject = tokenService.getType(token);
To get all claims from JWT token payload call method claims(String token)
on TokenService
public class Main {
public static void main(String[] args) {
String token="eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJhbmRyb3Nvcjk5QGdtYWlsLmNvbSIsImlkIjozLCJyb2xlcyI6WyJST0xFX1VTRVIiXSwiZXhwIjoxNzE3MTQ1MDIxfQ.w8ZFLFsKf7Qs9_dNb0WzdoyAIpWtfeEyqLfNI_G16_6NHbGwCRbeVVm_a_DzckytsyGYHTWRlZdi_gWK-HjrXg";
Map<String, Object>;
claims.forEach((key,value)->System.out.println(key + " " + value));
To get claim by its name from JWT token payload call method claim(String token, String key)
on TokenService
public class Main {
public static void main(String[] args) {
String token="eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJhbmRyb3Nvcjk5QGdtYWlsLmNvbSIsImlkIjozLCJyb2xlcyI6WyJST0xFX1VTRVIiXSwiZXhwIjoxNzE3MTQ1MDIxfQ.w8ZFLFsKf7Qs9_dNb0WzdoyAIpWtfeEyqLfNI_G16_6NHbGwCRbeVVm_a_DzckytsyGYHTWRlZdi_gWK-HjrXg";
String claim = (String) tokenService.claim(token, "subject");
See active issues at issues page