Kotlin / Android JWT generator quickstart
Create a token with your public API key in the sub claim, a near-term Unix timestamp in exp, and an HS256 signature made with your private API key.
Sapling JWTs use HS256 with a
sub claim containing your public API key and an exp claim containing a Unix timestamp. The examples use a one-hour lifetime; shorten it further when your application can refresh tokens easily.
Kotlin / Android
HS256 · sub + exp
This example uses com.auth0:java-jwt.
import com.auth0.jwt.JWT
import com.auth0.jwt.algorithms.Algorithm
import java.time.Instant
import java.util.Date
fun main() {
val publicKey = System.getenv("SAPLING_PUBLIC_KEY")
?: error("Set SAPLING_PUBLIC_KEY first.")
val privateKey = System.getenv("SAPLING_PRIVATE_KEY")
?: error("Set SAPLING_PRIVATE_KEY first.")
val token = JWT.create()
.withSubject(publicKey)
.withExpiresAt(Date.from(Instant.now().plusSeconds(3600)))
.sign(Algorithm.HMAC256(privateKey))
println(token)
}
Generated token
text/plain
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.<base64url-claims>.<signature>
Return the compact token to the browser and pass it to Sapling.init as the key. Issue a fresh token after it expires; never send the private key.
About Kotlin / Android
Kotlin is a programming language that interoperates with Java on the JVM. While it is cross-platform, widespread adoption of Kotlin stems from its first-class support on the Android platform for Android applications.