JWT Token Exchange Rule
Defines a JWT token that is being issued.
The various claims of the issued token can be configured along with the issued token type and signature.
Note that the iss claim cannot be configured explicitly and will instead automatically be set to the value of the issuer ID of the AS where the token exchange grant is configured. If no issuer ID is configured, the issued token will not contain an iss claim.
condition) subjectTokenValidation) actorTokenValidation) Defines the validation of the actor token. If left empty, actor tokens are ignored.
If the validation fails, this rule does not issue a token and is skipped.
issuedTokenType) validityLifetime) Lifetime of the issued token.
Security warning: This should be chosen as short as possible.
audienceClaim) Defines the "aud" claim of the issued token.
If the claim is configured but the resulting value is empty, the token exchange will fail.
subjectClaim) Defines the "sub" claim of the issued token.
If the evaluated value is not of type String, empty or blank, the token exchange will fail.
actorClaim) Defines the "act" claim of the issued token.
If not defined, no "act" claim is added.
clientIdClaim) Defines the "client_id" claim of the issued token.
If not defined, no "client_id" claim is added.
scopeClaim) Defines the "scope" claim and token exchange "scope" response parameter.
If no plugin is configured, the scope of the issued token will be empty.
customClaims) signature) The signature of the issued token.
The signature verification data can be obtained from the JWKs Endpoint.
Security Warning: The signature must be verified by the consumer of the JWT before the content is interpreted.
type: OAuth2TokenExchangeJwtRule
id: OAuth2TokenExchangeJwtRule-xxxxxx
displayName:
comment:
properties:
actorClaim:
actorTokenValidation:
audienceClaim:
clientIdClaim:
condition:
customClaims:
issuedTokenType: JWT
scopeClaim:
signature:
subjectClaim:
subjectTokenValidation:
validityLifetime: 180