menu

Step Up API Authentication

If you haven't already done so, please read our Basic API Authentication Guide here.

Basic information about JWT

  • A JSON Web Token("JWT") is used by TxB partners who interact with our APIs on behalf of more than 1 client
  • A JWT consists of a header, payload and a signature
  • RSA key(private) with a unique 'kid' is used to sign the JWT. Partner exchanges public RSA key with TxB which will be used to validate the signature
  • The claim in the payload has various identifiers namely, client(subject), partner(issuer), audience(txb), kid(from RSA key), sha256 hash of the mTLS cert

The guide below describes how to create and bind a JWT token, which may be included in the Authentication input parameter and which will be presented alongside the mTLS certificate.

Step by Step Guide

Step 1 - Generate a public JWK using RSA KeyPair

Generate a one-time unique key ID:

String uniqueKeyId = String.valueOf(UUID.randomUUID())

This unique key Id will be used in RSAKey generation (this step) and also used again in Step 3 during JWT generation.

You can use uuid generator tools to create this via code or via tools available online.

Generate public JWK using a one-time generated RSA Key:

RSAKey rsaKey = new RSAKeyGenerator(2048)
    .keyUse(KeyUse.SIGNATURE) // indicate the intended use of the key
    .keyID(uniqueKeyId) //This static key Id will be used again in Step 3
    .generate();
return rsaKey.toPublicJWK();

This is a one-time key setup and will be used in Step 3 to sign the JWT.

Send the output of rsaKey.toPublicJWK() to TxB.


Step 2 - Calculate the certificate hash using thumbprint

Once you have the mTLS certificate, copy the text into the mTLSCert variable and run the code below to create the X509Certificate object

String mTLSCert = "-----BEGIN CERTIFICATE-----\n"
                    +  "MIIFtzCCA5+gAwIBAgIRAJn6k32RASsmv/BtZ237xMAwDQYJKoZIhvcNAQELBQAw\n"
                    -----------------------------------------------------------------------
                    -----------------------------------------------------------------------
                    -----------------------------------------------------------------------
                    + "-----END CERTIFICATE-----\n";

InputStream targetStream = new ByteArrayInputStream(mTLSCert.getBytes());
CertificateFactory certificateFactory = CertificateFactory.getInstance("X.509");
X509Certificate x509cert = (X509Certificate) certificateFactory.generateCertificate(targetStream);

Compute the SHA256 hash of the X509Certificate object using below code:

private static String getThumbprint(X509Certificate cert)
        throws NoSuchAlgorithmException, CertificateEncodingException {
    MessageDigest md = MessageDigest.getInstance("SHA-256");
    byte[] der = cert.getEncoded();
    md.update(der);
    byte[] digest = md.digest();
    String digestHex = DatatypeConverter.printHexBinary(digest);
    return digestHex.toLowerCase();
}

private static String calculateSHA256(X509Certificate x509cert) {
    String thumbprint = getThumbprint(x509cert);
    byte[] decodedHex = Hex.decodeHex(x509cert);
    return new String(Base64.getUrlEncoder().encode(
        decodedHex)).replaceAll("=+$", "");
}

An example output of the SHA256 hash is - ikVs7R7oXt0Ll_EGWWCE6VaJv6myadr9giDODCzbvtM. This value will be used in the JWT payload in step 3


Step 3 - Bind all of values together in JWT

Create a JWTClaims object:

JwtClaims claims = new JwtClaims();

Set Expiration time on the claim:

claims.setExpirationTimeMinutesInTheFuture(5);

Set the Partner Identifier provided by TxB:

claims.setIssuer("0EAA62456B3426NU962A296BC4C5F9C9"); // This will be the gseid value in the mTLS cert

Set the Client Identifier provided by TxB:

claims.setSubject("7FNA456B34268NU6G9682A2964C5967F"); // This value will change based on the third party account

Set the audience as txb:

claims.setAudience("txb");

Set a random ID for JWTId:

claims.setJwtId(String.valueOf(UUID.randomUUID()));

Set Current time as issuedAt time:

claims.setIssuedAtToNow();

Set value of kid from Step 1:

claims.setClaim("kid", uniqueKeyId);

Set cnf#x5t#S256 from output of Step 2:

claims.setClaim("cnf#x5t#S256", calculateSHA256(x509cert));

Sign the JWT using the RSAKey from Step 1:

JsonWebSignature jws = new JsonWebSignature();
jws.setPayload(claims.toJson());
jws.setAlgorithmHeaderValue(AlgorithmIdentifiers.RSA_USING_SHA256);
jws.setKey(rsaKey.toPrivateKey()); // From Step 1
jws.setDoKeyValidation(false); // relaxes the key length requirement

Finally, return the JWT Output:

String jwtOut = jws.getCompactSerialization();
return jwtOut;

Your JWT will look something like this:

eyJhbGciOiJSUzI1NiJ9.eyJleHAiOjE2MDEyNjMyNzgsInN1YiI6IjdGTkE0NTZCMzQyNjhOVTZHOTY4MkEyOTY0QzU5NjdGIiwiYXVkIjoidHhiIiwianRpIjoiYjI5NGMxZjMtY2Y3OC00OTU4LWI3OGMtYTM0ZGE5MDhlMGM3IiwiaXNzIjoiMEVBQTYyNDU2QjM0MjZOVTk2MkEyOTZCQzRDNUY5QzkiLCJpYXQiOjE2MDEyNjI5NzgsImtpZCI6ImFlODVmZWU0LWQ5OGQtNGI4NS1iMDM0LTI5ZTgzMGE5ZjA0NyIsImNuZiN4NXQjUzI1NiI6ImlrVnM3UjdvWHQwTGxfRUdXV0NFNlZhSnY2bXlhZHI5Z2lET0RDemJ2dE0ifQ.fFuBynWjCcsmvye0kbI-ZAIqEXrLqvv9BFU13ZRoKcf54sQTUaguMubVQP4u1S1IijxyUMrFJpygzjbBQL_xzVRaUVXTPlrYM8HlugjsE-t94D085Y9ULJmDNbsGALwnA5ftv0O3cUH7qckmtIvUWI58vH6BvMYoS6T4ANiwXNxux7d81bGqy7r4a-IJH1umCLaz-cprhyb8J5SJkNhx4m5CJWGIyg5ycpF0PNUDX3HjxcACilXPQMGAKtQkV89EzzGFDc-j46aQ0920ocf9u_LfmavfYABasEtX9E0j8TKnAS1RZosKoCbj14OV8sYhNgKm9BIvk32aS2VfwpkMfQ

Step 4 - Test final connection

Finally, test your connection using this cURL command:


curl -s -X GET "https://api.test.txb.gs.com/v1/connectivity" -H "Authorization: Bearer <jwtOut>" --cacert ./certificate.pem --key private_key.key


Certain solutions and Institutional Services described herein are provided via our Marquee platform. The Marquee platform is for institutional and professional clients only. This site is for informational purposes only and does not constitute an offer to provide the Marquee platform services described, nor an offer to sell, or the solicitation of an offer to buy, any security. Some of the services and products described herein may not be available in certain jurisdictions or to certain types of clients. Please contact your Goldman Sachs sales representative with any questions. Any data or market information presented on the site is solely for illustrative purposes. There is no representation that any transaction can or could have been effected on such terms or at such prices. Please see https://www.goldmansachs.com/disclaimer/sec-div-disclaimers-for-electronic-comms.html for additional information.
Transaction Banking services are offered by Goldman Sachs Bank USA (“GS Bank”). GS Bank is a New York State chartered bank, a member of the Federal Reserve System and a Member FDIC.
GS DAP™ is owned and operated by Goldman Sachs. This site is for informational purposes only and does not constitute an offer to provide, or the solicitation of an offer to provide access to or use of GS DAP™. Any subsequent commitment by Goldman Sachs to provide access to and / or use of GS DAP™ would be subject to various conditions, including, amongst others, (i) satisfactory determination and legal review of the structure of any potential product or activity, (ii) receipt of all internal and external approvals (including potentially regulatory approvals); (iii) execution of any relevant documentation in a form satisfactory to Goldman Sachs; and (iv) completion of any relevant system / technology / platform build or adaptation required or desired to support the structure of any potential product or activity.
Mosaic is a service mark of Goldman Sachs & Co. LLC. This service is made available in the United States by Goldman Sachs & Co. LLC and outside of the United States by Goldman Sachs International, or its local affiliates in accordance with applicable law and regulations. Goldman Sachs International and Goldman Sachs & Co. LLC are the distributors of the Goldman Sachs Funds. Depending upon the jurisdiction in which you are located, transactions in non-Goldman Sachs money market funds are affected by either Goldman Sachs & Co. LLC, a member of FINRA, SIPC and NYSE, or Goldman Sachs International. For additional information contact your Goldman Sachs representative. Goldman Sachs & Co. LLC, Goldman Sachs International, Goldman Sachs Liquidity Solutions, Goldman Sachs Asset Management, L.P., and the Goldman Sachs funds available through Goldman Sachs Liquidity Solutions and other affiliated entities, are under the common control of the Goldman Sachs Group, Inc.
© 2024 Goldman Sachs. All rights reserved.