Java SDK
The Java SDK is a Gradle multi-module project targeting JDK 17. Its current source and publication state is listed below.
Packages
Section titled “Packages”| Surface | Package or module | Release status |
|---|---|---|
| Connect | com.sudomimus:sudomimus-connect | Planned |
| Session | com.sudomimus:sudomimus-session | Planned |
| Device | — | No package |
| Native | com.sudomimus:sudomimus-native | Planned |
| Token | com.sudomimus:sudomimus-token | Source only |
Release status verified: .
The stable token module is currently available from source and is not published to Maven Central.
Until a version appears as Published above, use a standards-based JOSE library
for production integrations instead of adding the future Maven coordinate.
Token Verification
Section titled “Token Verification”Use the token module in services that receive Sudomimus JWTs and need local verification. Resolve the token’s kid from the configured application’s Session JWK Set at GET /applications/{applicationAnchor}/jwks.json; do not derive the URL from an untrusted audience. Cache the set according to its HTTP response headers and refresh once when a kid is unknown.
The verification contract matches the other SDKs: parse the JWT, require RS256 and the expected token kind and audience, require a non-empty kid, check expiration, select that JWK, and verify the RSA-SHA256 signature.