JWT Scope Validation

Validates that the JWT token includes specific scopes

Configuration#

{
  "name": "my-jwt-scopes-inbound-policy",
  "policyType": "jwt-scopes-inbound",
  "handler": {
    "export": "JWTScopeValidationInboundPolicy",
    "module": "$import(@zuplo/runtime)",
    "options": {
      "scopes": [
        "read:users",
        "write:projects"
      ]
    }
  }
}

Options#

  • name the name of your policy instance. This is used as a reference in your routes.
  • policyType the identifier of the policy. This is used by the Zuplo UI. Value should be jwt-scopes-inbound.
  • handler/export The name of the exported type. Value should be JWTScopeValidationInboundPolicy.
  • handler/module the module containing the policy. Value should be $import(@zuplo/runtime).
  • handler/options The options for this policy:
    • scopes

      An array of of JWT scopes

Was this article helpful?

Do you have any questions?Contact us
Check out ourproduct changelog