OSS TanbouSign in with GitHub

create, sign, parse, and validate JSON Web Tokens in Go

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
9,229
Primary language
Go
License
MIT
Repository last updated
Sep 14, 2026
On this page

Overview

golang-jwt/jwt is a Go implementation of RFC 7519 JSON Web Tokens. It supports token creation and signing, parsing and signature verification, registered and custom claims validation, and signing methods including HMAC SHA, RSA, RSA-PSS, and ECDSA.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Create claim-bearing JWTs and sign them with explicit algorithms and keys

APIs such as NewWithClaims construct Tokens with headers and claims, then SigningMethod implementations produce compact JWT strings using HMAC, RSA, RSA-PSS, ECDSA, and extensible custom methods.

Sources: [2]

Use parser options to verify signatures and enforce registered-claim policy

Parsing verifies signatures and can enforce expiration, not-before, issuer, audience, and other application policies. Version 5.3.1 adds the WithNotBeforeRequired parser option.

Sources: [2][4]

Best fit

Fits Go backends that issue or validate bearer and service tokens

It is useful for OAuth2/OIDC-adjacent bearer tokens, internal service tokens, and signed claims where JWT encoding and signature verification live inside the application.

Sources: [2]

Before adoption

v5.3.1 declares Go 1.21; always constrain the received alg to the expected signing method

The v5.3.1 go.mod declares Go 1.21, and the project follows Go's official support policy. The README explicitly warns applications to verify that a token's alg matches expectations; alg=none is rejected unless a special unsafe key is supplied. Key selection, issuer and audience checks, and clock policy should also be explicit.

Sources: [3][2][4]

Official sources

  1. [1]golang-jwt/jwt — GitHub repository(2026-10-06)
  2. [2]golang-jwt v5.3.1 — README(2026-10-06)
  3. [3]golang-jwt v5.3.1 — go.mod(2026-10-06)
  4. [4]golang-jwt v5.3.1 release(2026-10-06)
  5. [5]golang-jwt MIT license(2026-10-06)
Supplemental curator note

A valid JWT signature is not enough by itself: explicitly constrain allowed algorithms and application claims such as issuer, audience, expiration, and not-before. Pin parser options and always match key types to the expected signing method.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/golang-jwt/jwt.git
  2. 2

    Enter the repository

    cd jwt
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

9,229 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
1
Open PRs
27

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • go
  • golang
  • jwt
  • auth
  • ed25519
  • security
Stars
9,229
Forks
451
Watchers
39
Open issues
30
Contributors
110
Owner type
Organization
Primary language
Go
License
MIT
Repository last updated
Sep 14, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?