{"repo":"atholbro/paseto","free":true,"listed":false,"github":"https://github.com/atholbro/paseto","clone":"git clone https://github.com/atholbro/paseto.git","description":"Java Implementation of Platform-Agnostic Security Tokens - https://paseto.io","language":"Kotlin","stars":42,"topics":["paseto","java","authentication","security","token","token-authetication","token-based-authentication","paseto-tokens","jwt","kotlin"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"PASETO: Platform-Agnostic Security Tokens A Kotlin/JVM Implementation of Platform-Agnostic Security Tokens - https://paseto.io Paseto is everything you love about JOSE (JWT, JWE, JWS) without any of the many design deficits that plague the JOSE standards. Table of Contents - What is Paseto? - Requirements - Installation - Usage - Token Version - Token Purpose - Keys - Key Generation - Key Loading - Key Rings - Key Lifecycles - Key Saving - Tokens - Standard Claims - Custom Claims - Footers - String Footers - Structured Claim Footers - Footer Verification During Decode - Footer Limits and Parsing - Footer Parsing Modes - Tainted Footers - Accessing Footer Claims - Rules Engine - Rule Execution - Built-in Rules - Default Rules - Custom Rules - Reusing Rule Sets What is Paseto? Paseto (Platform-Agnostic SEcurity TOkens) is a specification and reference implementation for secure stateless tokens. Key Differences between Paseto and JWT Unlike JSON Web Tokens (JWT), which gives developers more than enough rope with which to hang themselves, Paseto only allows secure operations. JWT gives you \"algorithm agility\", Paseto gives you \"versioned protocols\". It's incredibly unlikely that you'll be able to use Paseto in an insecure way. Caution: Neither JWT nor Paseto were designed for stateless session management. Paseto is suitable for tamper-proof cookies, but cannot prevent replay attacks by itself. --- Requirements - JDK 17+ Supported Paseto Versions Type V1 V2 V3 V4 :------: :--: :--","default_branch":null,"files":null,"tree":[],"storefront":"/r/atholbro","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/atholbro/paseto/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}