Sapling Logo
SDK authentication quickstart

JavaScript JWT Generator

Sign a short-lived Sapling SDK credential in JavaScript without exposing your private API key to browser code.

  • HS256 signature
  • Server-side only
  • Public + private keys
SIGN JavaScript logo JavaScript HS256 · sub + exp

JavaScript JWT generator quickstart

Create a token with your public API key in the sub claim, a near-term Unix timestamp in exp, and an HS256 signature made with your private API key.

Sapling JWTs use HS256 with a sub claim containing your public API key and an exp claim containing a Unix timestamp. The examples use a one-hour lifetime; shorten it further when your application can refresh tokens easily.
JavaScript HS256 · sub + exp

Install jsonwebtoken and run this example in Node.js, not in the browser.

const jwt = require('jsonwebtoken');

const publicKey = process.env.SAPLING_PUBLIC_KEY;
const privateKey = process.env.SAPLING_PRIVATE_KEY;
if (!publicKey || !privateKey) {
  throw new Error(
    'Set SAPLING_PUBLIC_KEY and SAPLING_PRIVATE_KEY first.',
  );
}

const token = jwt.sign(
  {sub: publicKey},
  privateKey,
  {algorithm: 'HS256', expiresIn: '1h'},
);

console.log(token);
Generated token text/plain
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.<base64url-claims>.<signature>

Return the compact token to the browser and pass it to Sapling.init as the key. Issue a fresh token after it expires; never send the private key.

About JavaScript

JavaScript is a scripting language used in browsers to provide client-side dynamic application behavior. Almost all websites use it. Additionally, JavaScript is also used in server-side applications through environments like Node.js. Cross-platform and desktop applications can be developed using the Electron framework.