On this page
Overview
JJWT is a pure-Java JOSE implementation for the JVM and Android. It covers JWT, JWS, JWE, JWK, JWA, and related RFCs with APIs for token creation, signing, verification, encryption, decryption, and key handling.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Handle JWT, JWS, JWE, and JWK in one Java library
The README documents RFC 7519 JWT, RFC 7515 JWS, RFC 7516 JWE, RFC 7517 JWK, RFC 7518 JWA, and related specifications.
Sources: [2]
Implement standard signature, encryption, and key-management algorithms
JJWT supports HMAC, RSA, RSA-PSS, ECDSA, EdDSA, AES-GCM, JWE key management, claim assertions, and secure key-generation helpers.
Sources: [2]
Best fit
Fits Java authentication and service-to-service token flows
It is useful when applications need signature verification plus JWK and JWE handling within the same API model.
Sources: [2]
Before adoption
Official sources
- [1]jwtk/jjwt — GitHub repository(2026-10-06)
- [2]JJWT — README(2026-10-06)
- [3]JJWT 0.13.0 release(2026-10-06)
Supplemental curator note
It fits services that need JWT signatures plus JWK and JWE in one Java API. Prefer the library's key generation and verification APIs instead of inventing algorithm or key-size handling.
Try it in 3 steps
- 1
Get the source
git clone --depth 1 https://github.com/jwtk/jjwt.git - 2
Enter the repository
cd jjwt - 3
Check the official steps
Continue with the commands in the README Installation, Quick Start, or Getting Started section.
find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Growth
Growth trends · Last 30 days
11,138 Stars
Trend data is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- jackson
- java
- java-jwt
- jjwt
- json
- jwe
- jwk
- jws
- jwt
- jwt-auth
- jwt-authentication
- jwt-claims
- Stars
- 11,138
- Forks
- 1,396
- Watchers
- 11,138
- Open issues
- 47
- Contributors
- 65
- Owner type
- Organization
- Primary language
- Java
- License
- Apache-2.0
- Repository last updated
- Oct 4, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- jose7,816 Stars
2 shared tag(s) · 2 shared category(s)
handle JWT, JWS, JWE, JWK, and JWKS with a zero-dependency Web-standard JOSE library
TypeScript - iron-session4,141 Stars
2 shared tag(s) · 2 shared category(s)
store session data in signed and encrypted cookies for stateless server-side sessions in Next.js
TypeScript - Keycloak37,151 Stars
2 shared tag(s) · 1 shared category(s) · Same language
an IAM server providing authentication and authorization to applications
Java - Gson24,235 Stars
2 shared tag(s) · 1 shared category(s) · Same language
serialize and deserialize Java objects to JSON without requiring annotations on every model
Java - SuperTokens Core15,335 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Self-host the authentication, session, and user-data core that frontend and backend SDKs call over HTTP
Java - OWASP Dependency-Check7,716 Stars
2 shared tag(s) · 1 shared category(s) · Same language
match project dependencies to CPE and CVE data and detect known vulnerabilities from CLI, Maven, Gradle, and other build integrations
Java
Report incorrect information
Tell us if any listing information is incorrect or outdated.