---
source_url: https://www.pubnub.com/docs/serverless-sdk/modules-and-libraries/jwt
title: jwt
updated_at: 2026-09-30T07:20:08.000Z
---

# jwt

## Documentation index

To discover more PubNub resources:

1. Fetch [PubNub's llms.txt](https://www.pubnub.com/llms-full.txt) for a list of available pages in Markdown format.
2. Identify relevant URLs from that index.
3. Fetch the target pages.

Do not assume a path exists, always check the index first.

The `jwt` built-in module is available only inside a PubNub Function. It creates, decodes, and verifies JSON Web Tokens (JWTs).

```javascript
const { sign, decode, verify } = require('jwt');
```

## sign

`sign(payload, secretOrPrivateKey, options?)`

| Parameter | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| payload | Object | Yes |  | Claims to encode in the token. |
| secretOrPrivateKey | String | Yes |  | Secret or private key used to sign the token. |
| options | Object | Optional |  | Signing options, for example `expiresIn`. |

Returns: the signed JWT, as a string.

```javascript
const jwt = require('jwt');
const payload = { userId: '123456', username: 'johndoe' };
const secretKey = 'your-256-bit-secret';
const token = jwt.sign(payload, secretKey, { expiresIn: '1h' });
```

## decode

`decode(token, {complete}?)`

| Parameter | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| token | String | Yes |  | Token to decode. |
| complete | Boolean | Optional |  | If `true`, returns the header and signature along with the payload. |

Returns: the token's payload. If `complete: true`, returns `{header, payload, signature}` instead. `decode()` does not verify the signature.

```javascript
const jwt = require('jwt');
const decoded = jwt.decode(token, { complete: true });
// { header: { alg: 'HS256', typ: 'JWT' }, payload: { userId: '123456', ... }, signature: '...' }
```

## verify

`verify(token, secretOrPublicKey, options?, callback?)`

| Parameter | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| token | String | Yes |  | Token to verify. |
| secretOrPublicKey | String | Yes |  | Secret or public key used to verify the signature. |
| options | Object | Optional |  | Verification options, for example expected claims. |
| callback | Function | Optional |  | Node-style callback. |

Returns: the decoded payload if verification succeeds. Throws if verification fails (tampering, expiration, or wrong key).

```javascript
const jwt = require('jwt');
try {
    const decoded = jwt.verify(token, secretKey);
    console.log('Decoded Payload:', decoded);
} catch (err) {
    console.error('Token verification failed:', err.message);
}
```

## Related reference

* [Modules and libraries](https://www.pubnub.com/docs/serverless-sdk/modules-and-libraries/overview.md). Every built-in module available inside a Function.

Last updated at: 2026-09-30T07:20:08.000Z
