You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PyJWT用RS256算法调用encode时报'Could not deserialize key data'错误

PyJWT使用RS256算法生成Token报错问题

此前使用PyJWT官方文档推荐的代码运行正常,但数月后无法工作。环境为Xubuntu系统,项目已Docker化。

问题代码

import jwt


SEC = "SECRET"

token = jwt.encode(
    {'name': ' ', 'admin': True}, SEC, algorithm='RS256'
)
print(token)

报错信息

Traceback (most recent call last):
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/jwt/algorithms.py", line 350, in prepare_key
    RSAPrivateKey, load_pem_private_key(key_bytes, password=None)
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/primitives/serialization/base.py", line 25, in load_pem_private_key
    return ossl.load_pem_private_key(
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 747, in load_pem_private_key
    return self._load_key(
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 929, in _load_key
    self._handle_key_loading_error()
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 984, in _handle_key_loading_error
    raise ValueError(
ValueError: ('Could not deserialize key data. The data may be in an incorrect format, it may be encrypted with an unsupported algorithm, or it may be an unsupported key type (e.g. EC curves with explicit parameters).', [<OpenSSLError(code=503841036, lib=60, reason=524556, reason_text=unsupported)>])

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "/home/cc/Documents/test/j.py", line 6, in <module>
    token = jwt.encode(
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/jwt/api_jwt.py", line 73, in encode
    return api_jws.encode(
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/jwt/api_jws.py", line 160, in encode
    key = alg_obj.prepare_key(key)
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/jwt/algorithms.py", line 353, in prepare_key
    return cast(RSAPublicKey, load_pem_public_key(key_bytes))
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/primitives/serialization/base.py", line 35, in load_pem_public_key
    return ossl.load_pem_public_key(data)
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 794, in load_pem_public_key
    self._handle_key_loading_error()
  File "/home/cc/Documents/test/venv/lib/python3.10/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 984, in _handle_key_loading_error
    raise ValueError(
ValueError: ('Could not deserialize key data. The data may be in an incorrect format, it may be encrypted with an unsupported algorithm, or it may be an unsupported key type (e.g. EC curves with explicit parameters).', [<OpenSSLError(code=75497580, lib=9, reason=108, reason_text=no start line)>])

使用的库版本

cffi==1.15.1
cryptography==39.0.0
pycparser==2.21
PyJWT==2.6.0

解决方法

核心原因

RS256属于非对称加密算法,要求必须使用RSA私钥作为签名密钥,普通字符串"SECRET"不符合RSA密钥的PEM格式,导致cryptography库无法解析。旧版PyJWT可能对密钥格式校验不严格,新版本修复了这个问题,因此之前能运行现在报错。

方案1:切换为对称加密算法(HS256)

如果不需要非对称加密的特性,直接改用HS256算法,该算法支持普通字符串作为密钥:

import jwt

SEC = "SECRET"

token = jwt.encode(
    {'name': ' ', 'admin': True}, SEC, algorithm='HS256'
)
print(token)

方案2:使用合法的RSA密钥对

如果必须使用RS256,需要先生成RSA私钥并在代码中使用:

  1. 生成RSA私钥(终端执行命令):
openssl genrsa -out private.pem 2048
  1. 修改代码读取私钥文件:
import jwt

with open("private.pem", "r") as f:
    private_key = f.read()

token = jwt.encode(
    {'name': ' ', 'admin': True}, private_key, algorithm='RS256'
)
print(token)

内容的提问来源于stack exchange,提问作者CC7052

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 19:59:59