{"repo":"nbaars/paseto4j","free":true,"listed":false,"github":"https://github.com/nbaars/paseto4j","clone":"git clone https://github.com/nbaars/paseto4j.git","description":"Paseto implementation for Java","language":"Java","stars":88,"topics":["paseto","jose","jwt","java","security","token-based-authentication","paseto-tokens"],"license":"MIT","category":"security-tools","readme_excerpt":"Java implementation of PASETO: Platform-Agnostic Security Tokens Implementation of PASETO library written in Java. This library is focused on taking part of the encryption/decryption part of the tokens it has a little dependencies as possible. How you construct the tokens with which JSON library is up to you. According to the specification the payload should always be a JSON object. Contents What is Paseto? Key Differences between Paseto and JWT Installation What is Paseto? Paseto is everything you love about JOSE (JWT, JWE, JWS) without any of the many design deficits that plague the JOSE standards. Paseto (Platform-Agnostic SEcurity TOkens) is a specification and reference implementation for secure stateless tokens. Key Differences between Paseto and JWT Unlike JSON Web Tokens (JWT), which gives developers more than enough rope with which to hang themselves, Paseto only allows secure operations. JWT gives you \"algorithm agility\", Paseto gives you \"versioned protocols\". It's incredibly unlikely that you'll be able to use Paseto in an insecure way. Caution: Neither JWT nor Paseto were designed for stateless session management. Paseto is suitable for tamper-proof cookies, but cannot prevent replay attacks by itself Installation There are four version available in Maven Central. Version 4 Add the following dependency to your project: Version 3 Version 3 is composed of NIST-approved algorithms, and will operate on tokens with the v3 version header. Add the following dependency t","default_branch":null,"files":null,"tree":[],"storefront":"/r/nbaars","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nbaars/paseto4j/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}