Username Ticket Key (usernameTicketKey)
Description
The ticket key for the username. The username in the 'sub' claim of the JWT will be written to the IAM ticket using this ticket key.
If using this ticket decoder for the loginapp's "SSO Ticket Feature", the value of this attribute must be "username".
Attributes
Example
username
Not Before Is Mandatory (notBeforeIsMandatory)
Description
If set to true, the incoming JWT must have a 'nbf' claim. Note that this setting does not affect validation of the 'nbf' claim. If this claim is present, it will always be validated.
Attributes
Default value
true
Valid Not Before Skew (validNotBeforeSkew)
Description
The configured value in seconds is added to the current time before validating the 'nbf' claim. The motivation to compare the 'nbf' claim with a time in the future is to avoid clock synchronization problems with the JWT issuer.
Attributes
Default value
5
Not Before Ticket Key (notBeforeTicketKey)
Description
The ticket key for the not before claim. The JWT not before claim ('nbf') will be written to that field. Note that this field is optional. If not set, the 'nbf' claim of the JWT won't be written into the ticket.
Attributes
Issued At Is Mandatory (issuedAtIsMandatory)
Description
If set to true, the incoming JWT must have a 'iat' claim.
Attributes
Default value
true
Issued At Ticket Key (issuedAtTicketKey)
Description
The ticket key for the issued at claim. The JWT issued at claim ('iat') will be written to that field. Note that this field is optional. If not set, the 'iat' claim of the JWT won't be written into the ticket.
Attributes
Issuer Is Mandatory (issuerIsMandatory)
Description
If set to true, the incoming JWT must have an 'iss' claim. Note that this setting does not affect validation of the 'iss' claim. If this claim is present, it will always be validated against the configured list of allowed issuers.
Attributes
Default value
true
Allowed Issuers (allowedIssuers)
Description
The allowed values for the issuer claim ('iss') in the JWT. If not configured, the issuer claim is not validated.
Attributes
Issuer Ticket Key (issuerTicketKey)
Description
The ticket key for the issuer claim. The JWT issuer claim ('iss') will be written to that field. Note that this field is optional. If not set, the 'iss' claim of the JWT won't be written into the ticket.
Attributes
Audience Is Mandatory (audienceIsMandatory)
Description
If set to true, the incoming JWT must have a 'aud' claim. Note that this setting does not affect validation of the 'aud' claim. If this claim is present, it will always be validated against the configured expected audience entry.
Attributes
Default value
false
Allowed Audiences (allowedAudiences)
Description
A list of accepted entries for the audience claim ('aud') of the JWT. If not configured, the audience claim is not validated. To pass validation there must be at least one entry that is present in the audience claim and in the configured list.
Attributes
Audience Ticket Key (audienceTicketKey)
Description
The ticket key for the audience claim. The JWT audience claim ('aud') will be written to that field. Note that this field is optional. If not set, the 'aud' claim of the JWT won't be written into the ticket.
Attributes
Jwt Id Is Mandatory (jwtIdIsMandatory)
Description
If set to true, the incoming JWT must have a 'jti' claim.
Attributes
Default value
false
Claims Stored As JSON (claimsStoredAsJson)
Description
The claim names that should be interpreted as JSON in the received JWT. If such a claim does not exist in the JWT, it is not written into the ticket. The ticket key is always the claim name. If the JSON of this claim is invalid, an exception is thrown.
Note: It is not allowed to specify registered claims here. Registered claims are always propagated as specified in RFC 7519.
Attributes
Jwt Id Ticket Key (jwtIdTicketKey)
Description
The ticket key for the JWT ID claim. The JWT ID claim ('jti') will be written to that field. Note that this field is optional. If not set, the 'jti' claim of the JWT won't be written into the ticket. In order to use the 'jti' claim as unique ID for the ticket, you must specify 'uniqueId' here. This is mandatory for Ticket-SSO-Setups.
Attributes
Example
uniqueId
Additional Claim Validators (additionalClaimValidators)
Description
List of additional claim validators.
Attributes
Assignable plugins
Signature Verifier (signatureVerifier)
Description
The settings that are used for verifying the MAC or signature of the JWT.
Attributes
Assignable plugins
Decrypter (decrypter)
Description
The settings that are used for decrypting the JWT. If no plugin is configured, the JWT must be unencrypted.
Attributes
Assignable plugins