← Back to plugin index

JWT Token Exchange Rule

Description

Defines a JWT token that is being issued.

The various claims of the issued token can be configured along with the issued token type and signature.

Note that the iss claim cannot be configured explicitly and will instead automatically be set to the value of the issuer ID of the AS where the token exchange grant is configured. If no issuer ID is configured, the issued token will not contain an iss claim.

Type name
OAuth2TokenExchangeJwtRule
Class
com.airlock.iam.oauth2.application.configuration.tokenexchange.rules.jwt.OAuth2TokenExchangeJwtRuleConfig
May be used by
License-Tags
OAuthTokenExchange
Properties
Condition (condition)
Description
Condition defining when this token may be issued.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Subject Token Validation (subjectTokenValidation)
Description
Subject Token Validation.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Actor Token Validation (actorTokenValidation)
Description

Defines the validation of the actor token. If left empty, actor tokens are ignored.

If the validation fails, this rule does not issue a token and is skipped.

Attributes
Plugin-Link
Optional
Assignable plugins
Issued Token Type (issuedTokenType)
Description
Type of the issued token that will be reflected in the response's JSON attribute "issued_token_type".
Attributes
Enum
Optional
Default value
JWT
Token Validity Lifetime [s] (validityLifetime)
Description

Lifetime of the issued token.

Security warning: This should be chosen as short as possible.

Attributes
Integer
Optional
Default value
180
Subject Claim (subjectClaim)
Description

Defines the "sub" claim of the issued token.

If the evaluated value is not of type String, empty or blank, the token exchange will fail.

Attributes
Plugin-Link
Optional
Assignable plugins
Actor Claim (actorClaim)
Description

Defines the "act" claim of the issued token.

If not defined, no "act" claim is added.

Attributes
Plugin-Link
Optional
Assignable plugins
Client Id Claim (clientIdClaim)
Description

Defines the "client_id" claim of the issued token.

If not defined, no "client_id" claim is added.

Attributes
Plugin-Link
Optional
Assignable plugins
Scope Claim (scopeClaim)
Description

Defines the "scope" claim and token exchange "scope" response parameter.

If no plugin is configured, the scope of the issued token will be empty.

Attributes
Plugin-Link
Optional
Assignable plugins
Custom Claims (customClaims)
Description
Defines the custom claims. Beware that standard claims can not be overwritten.
Attributes
Plugin-List
Optional
Assignable plugins
Signature (signature)
Description

The signature of the issued token.

The signature verification data can be obtained from the JWKs Endpoint.

Security Warning: The signature must be verified by the consumer of the JWT before the content is interpreted.

Attributes
Plugin-Link
Mandatory
Assignable plugins
YAML Template (with default values)

type: OAuth2TokenExchangeJwtRule
id: OAuth2TokenExchangeJwtRule-xxxxxx
displayName: 
comment: 
properties:
  actorClaim:
  actorTokenValidation:
  audienceClaim:
  clientIdClaim:
  condition:
  customClaims:
  issuedTokenType: JWT
  scopeClaim:
  signature:
  subjectClaim:
  subjectTokenValidation:
  validityLifetime: 180