go-jwt
JWT authentication package providing access tokens and refresh tokens with fingerprinting, Redis storage, and automatic refresh capabilities
About go-jwt
Last updated: 2026-10-07
[!NOTE] This README was generated by SKILL, get the ZH version from here.
A Go JWT authentication library with refresh token rotation, Redis-backed revocation, and Gin middleware
Table of Contents
Features
go get github.com/pardnchiu/go-jwt@latest· import pathgithub.com/pardnchiu/go-jwt/core· Documentation
- Redis-Controlled Token Lifecycle — An Access Token must pass both the ES256 signature and a Redis JTI whitelist, so logout writes a revocation record that takes effect immediately instead of waiting for JWT expiry.
- Device Fingerprint Binding — A SHA-256 fingerprint of OS, browser, device type, and device ID binds both the Access Token and Refresh ID, so a stolen token fails on any other device.
- Lock-Guarded Transparent Refresh — Expired tokens are re-signed from the Refresh ID automatically, and a
SETNXlock with Lua compare-and-delete unlock ensures one refresh per Refresh ID across instances. - Versioned Refresh ID Rotation — The full token pair is reissued once refreshes exceed
MaxVersionor the remaining TTL drops below a threshold; otherwise only the Access Token is re-signed to keep Redis writes low. - ES256 Auto Keys with Dual Middleware — Keys load from file paths or inline PEM, or a P-256 key pair is generated on first start, with drop-in Gin and
net/httpmiddleware.
Architecture
graph TB
REQ[HTTP Request] --> MW[Gin / net/http Middleware]
MW --> V[Verify]
V --> FP[Device Fingerprint]
V -->|Signature + JTI valid| OK[Return Auth]
V -->|Access Token expired or missing| RF[Refresh]
RF -->|Below threshold| RS[Re-sign Access Token]
RF -->|Over MaxVersion / TTL threshold| CR[Create full reissue]
V --> REDIS[(Redis)]
RF --> REDIS
License
This project is licensed under the MIT LICENSE.
Author
Just open an issue to share an idea.
©️ 2025 邱敬幃 Pardn Chiu
Frequently Asked Questions
What is go-jwt?
go-jwt is a Authentication and Authorization library for the Go programming language. JWT authentication package providing access tokens and refresh tokens with fingerprinting, Redis storage, and automatic refresh capabilities
How do I install go-jwt?
Install go-jwt with the Go module system using `go get pardnchiu/go-jwt`. Check the repository for the current installation instructions.
What category does go-jwt belong to?
go-jwt is listed under Authentication and Authorization, specifically Authentication and Authorization.