go-jose

The canonical Go implementation of JSON Web Encryption, Signature, and Token standards (JWE, JWS, JWT).

Library
Go
vv4.1.5
537 stars
Apache License 2.0

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
75 /100 Good
Development Activity 72
Maintenance 64
Community 76
Maturity 60
Momentum 28

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
84 /100 Excellent
Architecture 88
Code Quality 90
Innovation 78
Learning Curve 80

go-jose is a Go implementation of the JOSE (JSON Object Signing and Encryption) family of standards, covering JSON Web Encryption (RFC 7516), JSON Web Signature (RFC 7515), and JSON Web Token (RFC 7519) in a single library. It supports both compact and full JWS/JWE JSON serialization, multi-recipient encryption, and nearly the entire algorithm surface defined by the JOSE RFCs, including RSA-OAEP, AES key wrap, ECDH-ES, AES-GCM key wrap, PBES2, HMAC, RSASSA, ECDSA, and EdDSA.

The library ships as github.com/go-jose/go-jose/v4, with JWT-specific helpers factored into a jwt subpackage and a small jose-util CLI for working with JOSE messages from a shell. It also vendors a forked version of Go’s encoding/json that enforces case-sensitive member matching, closing a class of interoperability bugs between go-jose and JOSE implementations in other languages. Maintained under the go-jose GitHub organization, the successor to Square’s original square/go-jose, it is one of the most widely depended-on cryptography libraries in the Go ecosystem.

What You Get

  • Full JWE/JWS/JWT support - encrypt, sign, and parse JSON Web Encryption, Signature, and Token objects in both compact and JSON serialization forms.
  • Broad algorithm coverage - RSA-OAEP, AES key wrap, AES-GCM key wrap, ECDH-ES, PBES2, HMAC, RSASSA-PKCS1/PSS, ECDSA, and EdDSA out of the box.
  • Multi-recipient encryption - a single JWE can be encrypted to multiple recipients using different key algorithms.
  • jwt subpackage - a typed JSONWebToken/Builder API with standard and custom claim validation (issuer, audience, expiry, not-before).
  • jose-util CLI - a bundled command-line tool for generating keys and signing/encrypting/decrypting JOSE messages from a shell.

Common Use Cases

  • Issuing and verifying JWTs - authentication services sign and validate access or ID tokens without depending on a bespoke JWT-only library.
  • Encrypting sensitive payloads for storage or transit - services use JWE to encrypt data such as PII or session state that must be decrypted only by the holder of a specific key.
  • Interop with non-Go JOSE implementations - the case-sensitive JSON fork and full RFC algorithm coverage make go-jose a safe choice when tokens must round-trip with clients in other languages.
  • Building custom identity or SSO systems - the low-level Encrypter/Signer interfaces let teams compose their own token issuance and verification flows on top of standards-compliant primitives.

Under The Hood

Architecture The library is organized around a small set of interfaces: Encrypter/Decrypter for JWE, Signer/Verifier for JWS, each backed by pluggable strategy types (contentCipher, keyGenerator, keyEncrypter, keyDecrypter in crypter.go) selected by KeyAlgorithm/ContentEncryption/SignatureAlgorithm string constants. JWT support in the jwt subpackage builds strictly on top of the base jose package’s ParseSignedCompact/ParseEncryptedCompact rather than duplicating serialization logic, and the jose-util CLI is a thin consumer of the same public API. This keeps the crypto core (asymmetric.go, symmetric.go, signing.go) fully decoupled from both serialization (jws.go, jwe.go) and the higher-level JWT convenience layer, so adding a new algorithm means implementing one interface rather than touching call sites throughout the codebase.

Tech Stack Written in pure Go (module targets Go 1.24) with no external runtime dependencies, relying entirely on the standard library’s crypto/rsa, crypto/ecdsa, crypto/ed25519, and crypto/elliptic packages for primitives. The repository vendors its own fork of encoding/json (in the json subpackage) to enforce case-sensitive struct tag matching, since JOSE’s JSON serialization is security-sensitive to case handling. CI runs go build and go test across two current Go release lines plus a scheduled govulncheck job, and the jose-util CLI subdirectory is exercised separately with cram-based shell tests.

Code Quality The project carries an extensive test suite, roughly one test file per production file (35 _test.go files against under 30 non-test .go files), plus dedicated fuzz targets for JWE, JWS, and JWT parsing under the fuzz directory. Errors are represented as package-level sentinel values (ErrCryptoFailure, ErrUnsupportedAlgorithm, ErrInvalidKeySize, etc.) that callers can compare against directly, rather than opaque strings, and exported types and functions carry doc comments throughout. CI enforces the test suite and a vulnerability scan on every push and pull request across supported Go versions.

What Makes It Unique go-jose is one of the few Go libraries that implements the JOSE standards as a coherent whole, JWE, JWS, and JWT together, rather than a JWT-only convenience wrapper around ad hoc signing code. Its case-sensitive JSON fork addresses a specific, easy-to-miss interoperability failure mode when Go services exchange tokens with implementations in other languages, and its algorithm coverage (including PBES2 password-based key wrapping and full ECDH-ES support) goes well beyond what most JWT-focused libraries expose.

Used by 21 apps in this directory

Go
58%
Apache 2.0

agent-orchestrator

AI Agents · AI Code Assistants · Developer Tools

13,014

A local desktop workspace that gives every coding task its own agent, Git branch, and worktree, then tracks tasks, pull requests, CI, and reviews for 27 coding agents on one live Kanban board.

View details
86
Repo Health
83
Technical
68
Dependency
Built with
Go 58%
TypeScript 39%
Updated today
Rust
66%
Apache 2.0

agentgateway

AI Development · Developer Tools · Mcp

5,268

An open source AI-native proxy that secures, observes, and governs agent-to-LLM, agent-to-tool, and agent-to-agent communication through MCP, A2A, and unified LLM routing.

View details
88
Repo Health
82
Technical
69
Dependency
Built with
Rust 66%
Go 23%
Updated today
Go
85%
Apache 2.0

Argo Workflows

Data Engineering · Devops

17,029

The most popular Kubernetes-native workflow engine for orchestrating containerized DAGs, ML pipelines, CI/CD, and parallel batch jobs at scale.

View details
96
Repo Health
90
Technical
68
Dependency
Built with
Go 85%
TypeScript 11%
Updated yesterday
Go
83%
Apache 2.0

Authelia

Authentication · Security

29,224

OpenID Certified SSO and MFA portal for securing self-hosted web applications behind reverse proxies.

View details
91
Repo Health
81
Technical
71
Dependency
Built with
Go 83%
TypeScript 15%
Updated today
Go
49%
MIT

Bytebase

Devops

14,545

An open-source database CI/CD and DevSecOps platform — schema migration review, GitOps-driven changes, data masking, and access control across MySQL, PostgreSQL, Oracle, Snowflake, MongoDB, and more.

View details
92
Repo Health
73
Technical
68
Dependency
Built with
Go 49%
TypeScript 43%
Updated today
Go
75%
AGPL 3.0

Coder

Code Editors · Developer Tools · Devops

16,920

Self-hosted cloud development environments and AI coding agents — defined in Terraform, connected via WireGuard, automatically shut down when idle.

View details
91
Repo Health
90
Technical
66
Dependency
Built with
Go 75%
TypeScript 23%
Updated today
Go
47%
Apache 2.0

e2a

AI Agents · Automation

193

Give your AI agents a real, authenticated email address — with SPF/DKIM-verified inbound, HMAC-signed delivery, WebSocket fan-out, and human-in-the-loop approval built in.

View details
78
Repo Health
80
Technical
72
Dependency
Built with
Go 47%
TypeScript 27%
Python 13%
Updated 4 days ago
Go
75%
Other

Flipt

Developer Tools · Devops

4,916

Git-native feature flag platform that stores, versions, and deploys feature toggles directly in your own Git repositories with no external database required.

View details
90
Repo Health
83
Technical
68
Dependency
Built with
Go 75%
TypeScript 24%
Updated yesterday
TypeScript
48%
AGPL 3.0

Grafana

Analytics · Monitoring

77,212

The open-source observability platform that unifies metrics, logs, and traces from any data source into dynamic, queryable dashboards.

View details
95
Repo Health
91
Technical
63
Dependency
Built with
TypeScript 48%
Go 47%
Updated today

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers