On this page
Overview
golang-jwt/jwt is a Go implementation of RFC 7519 JSON Web Tokens. It supports token creation and signing, parsing and signature verification, registered and custom claims validation, and signing methods including HMAC SHA, RSA, RSA-PSS, and ECDSA.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Create claim-bearing JWTs and sign them with explicit algorithms and keys
APIs such as NewWithClaims construct Tokens with headers and claims, then SigningMethod implementations produce compact JWT strings using HMAC, RSA, RSA-PSS, ECDSA, and extensible custom methods.
Sources: [2]
Best fit
Fits Go backends that issue or validate bearer and service tokens
It is useful for OAuth2/OIDC-adjacent bearer tokens, internal service tokens, and signed claims where JWT encoding and signature verification live inside the application.
Sources: [2]
Before adoption
v5.3.1 declares Go 1.21; always constrain the received alg to the expected signing method
The v5.3.1 go.mod declares Go 1.21, and the project follows Go's official support policy. The README explicitly warns applications to verify that a token's alg matches expectations; alg=none is rejected unless a special unsafe key is supplied. Key selection, issuer and audience checks, and clock policy should also be explicit.
Official sources
- [1]golang-jwt/jwt — GitHub repository(2026-10-06)
- [2]golang-jwt v5.3.1 — README(2026-10-06)
- [3]golang-jwt v5.3.1 — go.mod(2026-10-06)
- [4]golang-jwt v5.3.1 release(2026-10-06)
- [5]golang-jwt MIT license(2026-10-06)
Supplemental curator note
A valid JWT signature is not enough by itself: explicitly constrain allowed algorithms and application claims such as issuer, audience, expiration, and not-before. Pin parser options and always match key types to the expected signing method.
Try it in 3 steps
- 1
Get the source
git clone --depth 1 https://github.com/golang-jwt/jwt.git - 2
Enter the repository
cd jwt - 3
Check the official steps
Continue with the commands in the README Installation, Quick Start, or Getting Started section.
find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Growth
Growth trends · Last 30 days
9,229 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 1
- Open PRs
- 27
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- go
- golang
- jwt
- auth
- ed25519
- security
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- imgproxy11,109 Stars
3 shared tag(s) · 1 shared category(s) · Same language
offload application image processing to a standalone HTTP service
Go - Unkey5,457 Stars
3 shared tag(s) · 1 shared category(s) · Same language
manage API keys, rate limits, RBAC, and gateway policy on one API platform
Go - jose7,816 Stars
3 shared tag(s) · 1 shared category(s)
handle JWT, JWS, JWE, JWK, and JWKS with a zero-dependency Web-standard JOSE library
TypeScript - Passbolt6,149 Stars
3 shared tag(s) · 1 shared category(s)
share and audit team credentials with user-owned keys and end-to-end encryption
PHP - Hanko9,034 Stars
3 shared tag(s) · Same language
API-first authentication from passkeys to SSO with native multi-tenancy
Go - Cosmos Server6,176 Stars
3 shared tag(s) · Same language
manage home-server apps, access, protection, and backups together
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.