Skip to content

Java SDK

View as Markdown

The Java SDK is a Gradle multi-module project targeting JDK 17. Its current source and publication state is listed below.

SurfacePackage or moduleRelease status
Connectcom.sudomimus:sudomimus-connectPlanned
Sessioncom.sudomimus:sudomimus-sessionPlanned
Device—No package
Nativecom.sudomimus:sudomimus-nativePlanned
Tokencom.sudomimus:sudomimus-tokenSource only

Release status verified: .

The stable token module is currently available from source and is not published to Maven Central. Until a version appears as Published above, use a standards-based JOSE library for production integrations instead of adding the future Maven coordinate.

Use the token module in services that receive Sudomimus JWTs and need local verification. Resolve the token’s kid from the configured application’s Session JWK Set at GET /applications/{applicationAnchor}/jwks.json; do not derive the URL from an untrusted audience. Cache the set according to its HTTP response headers and refresh once when a kid is unknown.

The verification contract matches the other SDKs: parse the JWT, require RS256 and the expected token kind and audience, require a non-empty kid, check expiration, select that JWK, and verify the RSA-SHA256 signature.