← Back to plugin index

JWT Ticket Encoder

Description

Configures the JWT (JSON Web Token) ticket encoder.

The encoder protects the integrity of the ticket by a MAC or signature according to the configured signer settings. It also has the ability to (optionally) encrypt the ticket if encrypter settings are configured.

Type name
JwtTicketEncoderSettings
Class
com.airlock.iam.common.application.configuration.jwt.JwtTicketEncoderSettings
May be used by
Properties
Username Ticket Key (usernameTicketKey)
Description
This defines the ticket value to be set as the subject field (sub) of the JWT. The corresponding key-value pair from the ticket is not added as a separate JWT claim.
Attributes
String
Mandatory
Suggested values
username
Issuer (issuer)
Description
The value for the issuer field (iss) in the JWT. If this value is set, the ticket must not contain a value for the key iss.
Attributes
String
Optional
Example
Airlock IAM
Audience (audience)
Description
The values for the audience field (aud) in the JWT. If a value is set, the ticket must not contain a value for the key aud. Note: If a single value is configured, it will be sent as string. If multiple values are configured an array is sent. This behaviour cannot be changed by specifying the aud claim in claimsStoredAsArray.
Attributes
String-List
Optional
Expiration Time [s] (expirationTime)
Description

Expiration time in seconds after which the JWT must not be accepted. If configured, a potentially defined expiration time in the ticket is overwritten. When left empty, the ticket's expiration date - if present - is unchanged.

Note: For security reasons, a short expiration time is preferable.

Attributes
Integer
Optional
Valid Not Before Skew [s] (validNotBeforeSkew)
Description
When generating a JWT, a JWT 'nbf' (not before) claim is added. This claim identifies the time before which the JWT must not be accepted for processing. To determine the 'nbf' in the JWT, the number of seconds configured in this property are subtracted from the JWT issue time. The motivation to set a time in the past is to avoid clock synchronization problems with the JWT receiver.
Attributes
Integer
Optional
Default value
5
Enforce JWT ID (enforceJwtId)
Description
The "jti" (JWT ID) claim provides a unique identifier for the JWT. This claim can be used to prevent the JWT from being replayed. A new JWT ID is applied only, when no ticket ID is set and no custom jti claim is defined.
Attributes
Boolean
Optional
Default value
true
Claims Stored As Array (claimsStoredAsArray)
Description
The keys of ticket fields that should be stored as array in the JWT. If such a key does not exist in the ticket an empty array is written into the JWT. Note: It is not allowed to specify registered claims here. Registered claims are always propagated as specified in RFC 7519. The aud claim will be sent as string if it is a single value and as array otherwise.
Attributes
String-List
Optional
Claims Stored As JSON (claimsStoredAsJson)
Description
The keys of ticket fields that should be stored as JSON in the JWT. If such a key does not exist in the ticket, the corresponding key is not written into the JWT. The claim name is always the ticket key. If the JSON is invalid, an exception is thrown.
Note: It is not allowed to specify registered claims here. Registered claims are always propagated as specified in RFC 7519. The aud claim will be sent as string if it is a single value and as array otherwise.
Attributes
String-List
Optional
Signer (signer)
Description
The settings that are used for signing the JWT.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Encrypter (encrypter)
Description
The settings that are used for encrypting the JWT. If no plugin is configured the JWT will be sent unencrypted.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: JwtTicketEncoderSettings
id: JwtTicketEncoderSettings-xxxxxx
displayName: 
comment: 
properties:
  audience:
  claimsStoredAsArray:
  claimsStoredAsJson:
  encrypter:
  enforceJwtId: true
  expirationTime:
  issuer:
  signer:
  usernameTicketKey:
  validNotBeforeSkew: 5