OSS TanbouSign in with GitHub

create and verify JWT, JWS, JWE, and JWK through an RFC-oriented fluent Java API

OSS scale score 291.5OSS health 100
About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
11,138
Primary language
Java
License
Apache-2.0
Repository last updated
Oct 4, 2026
On this page

Overview

JJWT is a pure-Java JOSE implementation for the JVM and Android. It covers JWT, JWS, JWE, JWK, JWA, and related RFCs with APIs for token creation, signing, verification, encryption, decryption, and key handling.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Handle JWT, JWS, JWE, and JWK in one Java library

The README documents RFC 7519 JWT, RFC 7515 JWS, RFC 7516 JWE, RFC 7517 JWK, RFC 7518 JWA, and related specifications.

Sources: [2]

Implement standard signature, encryption, and key-management algorithms

JJWT supports HMAC, RSA, RSA-PSS, ECDSA, EdDSA, AES-GCM, JWE key management, claim assertions, and secure key-generation helpers.

Sources: [2]

Best fit

Fits Java authentication and service-to-service token flows

It is useful when applications need signature verification plus JWK and JWE handling within the same API model.

Sources: [2]

Before adoption

Treat algorithm and key management as explicit security policy

Applications should define algorithm selection, key rotation, and claim validation rather than reimplementing cryptographic rules. The 0.13.0 release note also describes the version line's Java compatibility transition.

Sources: [2][3]

Official sources

  1. [1]jwtk/jjwt — GitHub repository(2026-10-06)
  2. [2]JJWT — README(2026-10-06)
  3. [3]JJWT 0.13.0 release(2026-10-06)
Supplemental curator note

It fits services that need JWT signatures plus JWK and JWE in one Java API. Prefer the library's key generation and verification APIs instead of inventing algorithm or key-size handling.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/jwtk/jjwt.git
  2. 2

    Enter the repository

    cd jjwt
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

11,138 Stars

Trend data is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • jackson
  • java
  • java-jwt
  • jjwt
  • json
  • jwe
  • jwk
  • jws
  • jwt
  • jwt-auth
  • jwt-authentication
  • jwt-claims
Stars
11,138
Forks
1,396
Watchers
11,138
Open issues
47
Contributors
65
Owner type
Organization
Primary language
Java
License
Apache-2.0
Repository last updated
Oct 4, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?