Encrypt and authenticate a short message as a Fernet token.
Fernet signs and encrypts a versioned token containing a timestamp, random IV, ciphertext, and HMAC tag; AES-CBC with PKCS7 padding protects the plaintext and HMAC-SHA256 authenticates the complete token fields. The key is split into signing and encryption halves.
db_password=Kx9!mP2$vL&7qR
Token: gAAAAABqjY5bs8WT5OOLmq9LVX1asy4zi_gPjOqCPqXeBc-MrK-v2bsM-ZxCKGqwf9uXZd-ls5Da_JVPj7csqY8rBEyZi3cESODehdYBV6rzOUoYkwMcrOw= Key: rCt4LSGZRjMN0PJiBC1eDfdjfsU82DJ4N9JdH3LxZeE= Note: Fernet token generated with AES-128-CBC encryption and HMAC-SHA256 authentication.
Encrypted cookies, background-job payloads, and TTL test fixtures use Fernet tokens.