I have a private key which looks like this:
-----BEGIN RSA PRIVATE KEY----- Some private key data -----END RSA PRIVA
First, you need to transform the private key to the form of RSA parameters using Bouncy Castle library. Then you need to pass the RSA parameters to the RSA algorithm as the private key. Lastly, you use the JWT library to encode and sign the token.
public string GenerateJWTToken(string rsaPrivateKey)
var rsaParams = GetRsaParameters(rsaPrivateKey);
var encoder = GetRS256JWTEncoder(rsaParams);
// create the payload according to your need
var payload = new Dictionary
{ "iss", ""},
{ "sub", "" },
// and other key-values
var token = encoder.Encode(payload, new byte[0]);
return token;
private static IJwtEncoder GetRS256JWTEncoder(RSAParameters rsaParams)
var csp = new RSACryptoServiceProvider();
var algorithm = new RS256Algorithm(csp, csp);
var serializer = new JsonNetSerializer();
var urlEncoder = new JwtBase64UrlEncoder();
var encoder = new JwtEncoder(algorithm, serializer, urlEncoder);
return encoder;
private static RSAParameters GetRsaParameters(string rsaPrivateKey)
var byteArray = Encoding.ASCII.GetBytes(rsaPrivateKey);
using (var ms = new MemoryStream(byteArray))
using (var sr = new StreamReader(ms))
// use Bouncy Castle to convert the private key to RSA parameters
var pemReader = new PemReader(sr);
var keyPair = pemReader.ReadObject() as AsymmetricCipherKeyPair;
return DotNetUtilities.ToRSAParameters(keyPair.Private as RsaPrivateCrtKeyParameters);
ps: the RSA private key should have the following format:
{base64 formatted value}