OIDC Private Key JWT Authentication
Description
Configures a client authentication that is based on a private_key_jwt.
The subject and issuer claim in the JWT must be equal to the identifier of a client (client_id). The client must have a public key registered in order to verify the signature of the JWT.
Note: JWTs are persisted, the 'jti' claim must be unique during the lifetime of a JWT (i.e. until it expires). If a JWT with a previously seen 'jti' claim is sent, authentication fails. Automatic removal of persisted JWTs (after expiry) can be configured in an OAuth 2.0 Clean-up Task.
May be used by
Properties
SQL Data Source (
sqlDataSource) Description
Defines where the JWT ID ('jti' claim of the JWT) is persisted.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Log Queries (
logQueries) Description
Enable to log SQL queries (only effective if the log level is at least INFO). Attention: query values (including potentially sensitive data) will be logged as well.
Attributes
Boolean
Optional
Default value
false
Tenant ID (
tenantId) Description
Identifier added to the database records to distinguish between different tenants.
If left empty, 'no_tenant' is used as the effective value for tenant ID.
Attributes
String
Optional
Length <= 50
Validation RegEx: (?!no_tenant$).*
Example
customerA
Example
customerB
YAML Template (with default values)
type: OpenIdConnectPrivateKeyJwtAuthentication
id: OpenIdConnectPrivateKeyJwtAuthentication-xxxxxx
displayName:
comment:
properties:
logQueries: false
sqlDataSource:
tenantId: