Skip to content

Signing a token

Sign tokens inside your own application with a standard JWT library — for example PyJWT (Python), jsonwebtoken (Node), jjwt (Java) or golang-jwt (Go). Mint a short-lived token and refresh it rather than holding a long-lived one:

import jwt  # PyJWT
from datetime import UTC, datetime, timedelta

now = datetime.now(tz=UTC)
token = jwt.encode(
    {
        "sub": ACCESS_KEY,
        "iat": int(now.timestamp()),
        "exp": int((now + timedelta(minutes=5)).timestamp()),
        "aud": API_URL,
        "iss": API_URL,
    },
    SIGNING_KEY,
    algorithm="RS256",  # or "HS256"
    headers={"kid": KEY_ID},
)

KEY_ID is your ACCESS KEY for HS256; for RS256 it is the id of the key pair LeanX issued you.

The same with jsonwebtoken (Node):

const jwt = require("jsonwebtoken");

const now = Math.floor(Date.now() / 1000); // seconds, not milliseconds
const token = jwt.sign(
  { sub: ACCESS_KEY, iat: now, exp: now + 300, aud: API_URL, iss: API_URL },
  SIGNING_KEY,
  { algorithm: "RS256", keyid: KEY_ID }, // or "HS256"
);

Never paste a SECRET KEY or an RS256 private key into a web-based JWT tool. jwt.io is useful for inspecting a token you already hold — decoding requires no key — but not for signing one.