Awesome Go

go-jwt

CategoryAuthentication and Authorization
SubcategoryAuthentication and Authorization
Stars20

JWT authentication package providing access tokens and refresh tokens with fingerprinting, Redis storage, and automatic refresh capabilities

About go-jwt

Last updated: 2026-10-07

[!NOTE] This README was generated by SKILL, get the ZH version from here.



A Go JWT authentication library with refresh token rotation, Redis-backed revocation, and Gin middleware

Table of Contents

Features

go get github.com/pardnchiu/go-jwt@latest · import path github.com/pardnchiu/go-jwt/core · Documentation

  • Redis-Controlled Token Lifecycle — An Access Token must pass both the ES256 signature and a Redis JTI whitelist, so logout writes a revocation record that takes effect immediately instead of waiting for JWT expiry.
  • Device Fingerprint Binding — A SHA-256 fingerprint of OS, browser, device type, and device ID binds both the Access Token and Refresh ID, so a stolen token fails on any other device.
  • Lock-Guarded Transparent Refresh — Expired tokens are re-signed from the Refresh ID automatically, and a SETNX lock with Lua compare-and-delete unlock ensures one refresh per Refresh ID across instances.
  • Versioned Refresh ID Rotation — The full token pair is reissued once refreshes exceed MaxVersion or the remaining TTL drops below a threshold; otherwise only the Access Token is re-signed to keep Redis writes low.
  • ES256 Auto Keys with Dual Middleware — Keys load from file paths or inline PEM, or a P-256 key pair is generated on first start, with drop-in Gin and net/http middleware.

Architecture

Full Architecture

graph TB
    REQ[HTTP Request] --> MW[Gin / net/http Middleware]
    MW --> V[Verify]
    V --> FP[Device Fingerprint]
    V -->|Signature + JTI valid| OK[Return Auth]
    V -->|Access Token expired or missing| RF[Refresh]
    RF -->|Below threshold| RS[Re-sign Access Token]
    RF -->|Over MaxVersion / TTL threshold| CR[Create full reissue]
    V --> REDIS[(Redis)]
    RF --> REDIS

License

This project is licensed under the MIT LICENSE.

Author

Just open an issue to share an idea.


©️ 2025 邱敬幃 Pardn Chiu

Frequently Asked Questions

What is go-jwt?

go-jwt is a Authentication and Authorization library for the Go programming language. JWT authentication package providing access tokens and refresh tokens with fingerprinting, Redis storage, and automatic refresh capabilities

How do I install go-jwt?

Install go-jwt with the Go module system using `go get pardnchiu/go-jwt`. Check the repository for the current installation instructions.

What category does go-jwt belong to?

go-jwt is listed under Authentication and Authorization, specifically Authentication and Authorization.

← Back to Authentication and Authorization