JWT Authentication Plugin for auth-proxy
A JWT (JSON Web Token) authentication plugin for the Modular Authenticating Reverse Proxy.
Installation
pip install auth-proxy-jwt
Features
- Validates JWT tokens from the Authorization header
- Configurable secret key and algorithm
- Optional audience and issuer validation
- Customizable claims mapping
- Forwards user identity and role information to backend services
Configuration
Add the JWT plugin to your auth-proxy configuration:
auth_plugins:
jwt:
secret: "your-secret-key"
algorithm: "HS256"
audience: "your-api"
issuer: "your-identity-provider"
require_exp: true
leeway: 10
header_prefix: "Bearer"
user_claim: "sub"
role_claim: "roles"
forward_claims: ["email", "permissions"]
paths:
- path: "^/api/.*$"
regex: true
authenticate: true
plugins: [jwt]
Configuration Options
| Option | Description | Default |
|---|---|---|
secret |
Secret key for validating token signatures | (required) |
algorithm |
JWT algorithm to use | "HS256" |
audience |
Expected audience claim | null |
issuer |
Expected issuer claim | null |
require_exp |
Whether to require expiration time | true |
leeway |
Leeway in seconds for expiration time | 0 |
header_prefix |
Authorization header prefix | "Bearer" |
user_claim |
Claim to use for user identity | "sub" |
role_claim |
Claim to use for role information | "role" |
forward_claims |
Additional claims to forward as headers | [] |
Headers Added to Backend Requests
When authentication succeeds, the plugin adds the following headers to the proxied request:
X-Auth-User: The user identity from the token (from the configureduser_claim)X-Auth-Role: The role or roles from the token (from the configuredrole_claim)X-Auth-Claim-{name}: Additional claims specified inforward_claims
License
This project is licensed under the MIT License - see the LICENSE file for details.
Metadata
Release files for auth-proxy-jwt 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| auth_proxy_jwt-0.2.0.tar.gz | 4.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| auth_proxy_jwt-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 10.8 kB
Release files / auth_proxy_jwt-0.2.0.tar.gz
| Download URL | auth_proxy_jwt-0.2.0.tar.gz |
|---|---|
| Size | 4.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0d80bf04c8672fb5891e3b52384c65221ec38257e78fca8370cbd6a431828f4a
|
|
BLAKE2b-256 checksum How to use checksums |
8d2f2b0cdcbd8684b1e66c72a10702dc956dd0b18842625b958c4b18761d4817
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.2
|
Release files / auth_proxy_jwt-0.2.0-py3-none-any.whl
| Download URL | auth_proxy_jwt-0.2.0-py3-none-any.whl |
|---|---|
| Size | 5.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7fdb06b00f3df4b1477eb217e112b4c273fee3caf643e749d69afc25444f6f3a
|
|
BLAKE2b-256 checksum How to use checksums |
5823ac7c2030d5b896e08c02c0bbc95fbdf88b6dd4d213c5fe368f8516917772
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.2
|