← Back to plugin index

OIDC Private Key JWT Authentication

Description
Configures a client authentication that is based on a private_key_jwt.

The subject and issuer claim in the JWT must be equal to the identifier of a client (client_id). The client must have a public key registered in order to verify the signature of the JWT.

Note: JWTs are persisted, the 'jti' claim must be unique during the lifetime of a JWT (i.e. until it expires). If a JWT with a previously seen 'jti' claim is sent, authentication fails. Automatic removal of persisted JWTs (after expiry) can be configured in an OAuth 2.0 Clean-up Task.

Type name
OpenIdConnectPrivateKeyJwtAuthentication
Class
com.airlock.iam.oauth2.application.configuration.clientauthentication.OpenIdConnectPrivateKeyJwtAuthenticationConfig
May be used by
License-Tags
OAuthServer
Properties
SQL Data Source (sqlDataSource)
Description
Defines where the JWT ID ('jti' claim of the JWT) is persisted.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Log Queries (logQueries)
Description
Enable to log SQL queries (only effective if the log level is at least INFO). Attention: query values (including potentially sensitive data) will be logged as well.
Attributes
Boolean
Optional
Default value
false
Tenant ID (tenantId)
Description

Identifier added to the database records to distinguish between different tenants.

If left empty, 'no_tenant' is used as the effective value for tenant ID.

Attributes
String
Optional
Length <= 50
Validation RegEx: (?!no_tenant$).*
Example
customerA
Example
customerB
YAML Template (with default values)

type: OpenIdConnectPrivateKeyJwtAuthentication
id: OpenIdConnectPrivateKeyJwtAuthentication-xxxxxx
displayName: 
comment: 
properties:
  logQueries: false
  sqlDataSource:
  tenantId: