Sign tokens inside your own application with a standard JWT library — for example PyJWT (Python), jsonwebtoken (Node), jjwt (Java) or golang-jwt (Go). Mint a short-lived token and refresh it rather than holding a long-lived one:
import jwt # PyJWT
from datetime import UTC, datetime, timedelta
now = datetime.now(tz=UTC)
token = jwt.encode(
{
"sub": ACCESS_KEY,
"iat": int(now.timestamp()),
"exp": int((now + timedelta(minutes=5)).timestamp()),
"aud": API_URL,
"iss": API_URL,
},
SIGNING_KEY,
algorithm="RS256", # or "HS256"
headers={"kid": KEY_ID},
)KEY_ID is your ACCESS KEY for HS256; for RS256 it is the id of the key pair LeanX issued you.
The same with jsonwebtoken (Node):
const jwt = require("jsonwebtoken");
const now = Math.floor(Date.now() / 1000); // seconds, not milliseconds
const token = jwt.sign(
{ sub: ACCESS_KEY, iat: now, exp: now + 300, aud: API_URL, iss: API_URL },
SIGNING_KEY,
{ algorithm: "RS256", keyid: KEY_ID }, // or "HS256"
);Never paste a SECRET KEY or an RS256 private key into a web-based JWT tool. jwt.io is useful for inspecting a token you already hold — decoding requires no key — but not for signing one.