We are trying to make a JWT token for Apple Search Ads using the KJUR jws library. We are using the API documents from Apple:
We are generating a private key (prime256v1 curve):
openssl ecparam -genkey -name prime256v1 -noout -out private-key.pem
Next we are generating a public key from the private key:
openssl ec -in private-key.pem -pubout -out public-key.pem
Next we setup the header and payload:
var tNow = KJUR.jws.IntDate.get('now');
var tEnd = KJUR.jws.IntDate.get('now + 1day');
var teamId = 'SEARCHADS.xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx';
var keyId = 'xxxxxx-xxxx-xxxx-xxxxxxxxxxx';
var privateKey = `-----BEGIN EC PRIVATE KEY-----
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
-----END EC PRIVATE KEY-----`;
var oHeader = {
"alg": "ES256",
"kid": keyId
}
var oPayload = {
"iss": teamId,
"iat": tNow,
"exp": tEnd,
"aud": "https://appleid.apple.com",
"sub": clientId
}
var sHeader = JSON.stringify(oHeader);
var sPayload = JSON.stringify(oPayload);
var sKey = KEYUTIL.getKey({d: privateKey, curve: 'prime256v1'});
var sResult = KJUR.jws.JWS.sign('ES256', sHeader, sPayload, sKey);
Next we try to validate the JWT token (it has generated a token) on jwt.io but cannot be verified. Apple search ads also throws a invalid_client message. What am i missing? Does anybody have a clue what I am doing wrong here?
Kind regards,
Jack Kwakman