Python 之 jwt 令牌生成和校验

JWT的生成与校验,核心是一个无状态的交互流程。服务器生成令牌后,客户端在后续请求中携带它,服务器只需验证令牌本身即可,无需保存会话状态。jwt 的交互流程如下。

Python 生成和校验 jwt 的常用方式有下面这几种。

itsdangerous

可以生成包含时间戳、对 URL 安全的签名令牌。一般用于生成轻量的非标准的 API 认证令牌。

python 复制代码
import uuid
import secrets
from itsdangerous.url_safe import URLSafeTimedSerializer as Serializer


def generate_secret_key():
    secret_key = secrets.token_hex(32)
    print(f"secret_key: {secret_key}")
    return secret_key


def generate_access_token():
    access_token = uuid.uuid1().hex
    print(f"access_token: {access_token}")
    return access_token


SECRET_KEY = generate_secret_key()
ACCESS_TOKEN = generate_access_token()


def encode_jwt(access_token):
    jwt = Serializer(secret_key=SECRET_KEY)
    return jwt.dumps(access_token)


def decode_jwt(jwt_token):
    jwt = Serializer(secret_key=SECRET_KEY)
    payload = jwt.loads(jwt_token)
    return payload


if __name__ == '__main__':
    payload = {"user_id": ACCESS_TOKEN, "username": "Looking"}
    auth_token = encode_jwt(payload)
    print(f"auth_token: {auth_token}")

    payload = decode_jwt(auth_token)
    print(f"payload: {payload}")
python 复制代码
secret_key: 2bcc46556f275ef90edf09104829aef4c2a8fd1c0f4d0c83d34e96b552518295
access_token: b6065d22a51711f1bbc2489ebd2d776f
auth_token: eyJ1c2VyX2lkIjoiYjYwNjVkMjJhNTE3MTFmMWJiYzI0ODllYmQyZDc3NmYiLCJ1c2VybmFtZSI6Ikxvb2tpbmcifQ.apU-JA.gjI87rWbCsIlQ2R-goAZOdDhJ5o
payload: {'user_id': 'b6065d22a51711f1bbc2489ebd2d776f', 'username': 'Looking'}

PYJWT

目前最核心、最流行的 JWT 库,它提供了最基础的生成与验证功能,是其他许多库的底层依赖。

python 复制代码
import jwt
import uuid
import secrets



def generate_secret_key():
    secret_key = secrets.token_hex(32)
    print(f"secret_key: {secret_key}")
    return secret_key


def generate_access_token():
    access_token = uuid.uuid1().hex
    print(f"access_token: {access_token}")
    return access_token


SECRET_KEY = generate_secret_key()
ACCESS_TOKEN = generate_access_token()


def encode_jwt(payload):
    token = jwt.encode(payload, SECRET_KEY, algorithm="HS256")
    return token


def decode_jwt(jwt_token):
    payload = jwt.decode(jwt_token, SECRET_KEY, algorithms=["HS256"])
    return payload


if __name__ == '__main__':
    payload = {"user_id": ACCESS_TOKEN, "username": "Looking"}
    auth_token = encode_jwt(payload)
    print(f"auth_token: {auth_token}")

    payload = decode_jwt(auth_token)
    print(f"payload: {payload}")
python 复制代码
secret_key: b56c0da985b4b5f0cecda3dce931ea1bec0340c6e0494cd280f20076acd91695
access_token: 52776fe6a51311f195a1489ebd2d776f
auth_token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyX2lkIjoiNTI3NzZmZTZhNTEzMTFmMTk1YTE0ODllYmQyZDc3NmYiLCJ1c2VybmFtZSI6Ikxvb2tpbmcifQ.ycHmDEYoXbIIZIwFXasVMTDW2ELzcp118YMJvW6xKao
payload: {'user_id': '52776fe6a51311f195a1489ebd2d776f', 'username': 'Looking'}
相关推荐
默_笙4 天前
🍙 给每个请求过安检:FastAPI 是怎么把校验写进类型注解的
python
qq_426003964 天前
启动playwright录制codegen生成自动化测试脚本
python·自动化
虎头金猫4 天前
4K 视频总卡在公网带宽?用 N1 + OpenList 把网盘播放链路重新理顺
运维·服务器·网络·python·容器·beautifulsoup·pandas
长沙三为智能科技4 天前
家政小程序开发从0到上线:五阶段交付流程与验收清单
python
伞伞悦读4 天前
【第38期】Python 模块与包详解:import、from、模块搜索路径、包结构和 __init__
开发语言·python
只睡四小时4 天前
Canvas 弹道联机实战:700 行 + 固定时间步长
python·websocket·html5·游戏开发·canvas
奇思妙想聪明勤奋的小羊4 天前
DeepAgents第5章:子Agent 与上下文隔离—让 Agent学会委派
人工智能·python·学习·语言模型
lpfasd1234 天前
2026年第38周GitHub趋势周报
python·科技·github
IZero074 天前
Jev 与 Laya
python·语言模型