Skip to main content

JWT Authentication Plugin for auth-proxy

A JWT (JSON Web Token) authentication plugin for the Modular Authenticating Reverse Proxy.

Installation

pip install auth-proxy-jwt

Features

  • Validates JWT tokens from the Authorization header
  • Configurable secret key and algorithm
  • Optional audience and issuer validation
  • Customizable claims mapping
  • Forwards user identity and role information to backend services

Configuration

Add the JWT plugin to your auth-proxy configuration:

auth_plugins:
  jwt:
    secret: "your-secret-key"
    algorithm: "HS256"
    audience: "your-api"
    issuer: "your-identity-provider"
    require_exp: true
    leeway: 10
    header_prefix: "Bearer"
    user_claim: "sub"
    role_claim: "roles"
    forward_claims: ["email", "permissions"]

paths:
  - path: "^/api/.*$"
    regex: true
    authenticate: true
    plugins: [jwt]

Configuration Options

Option Description Default
secret Secret key for validating token signatures (required)
algorithm JWT algorithm to use "HS256"
audience Expected audience claim null
issuer Expected issuer claim null
require_exp Whether to require expiration time true
leeway Leeway in seconds for expiration time 0
header_prefix Authorization header prefix "Bearer"
user_claim Claim to use for user identity "sub"
role_claim Claim to use for role information "role"
forward_claims Additional claims to forward as headers []

Headers Added to Backend Requests

When authentication succeeds, the plugin adds the following headers to the proxied request:

  • X-Auth-User: The user identity from the token (from the configured user_claim)
  • X-Auth-Role: The role or roles from the token (from the configured role_claim)
  • X-Auth-Claim-{name}: Additional claims specified in forward_claims

License

This project is licensed under the MIT License - see the LICENSE file for details.

Metadata

Release files for auth-proxy-jwt 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for auth-proxy-jwt 0.2.0
File Size Uploaded
auth_proxy_jwt-0.2.0.tar.gz 4.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for auth-proxy-jwt 0.2.0
File Interpreter ABI Platform
auth_proxy_jwt-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 10.8 kB

Release files / auth_proxy_jwt-0.2.0.tar.gz

Download URL auth_proxy_jwt-0.2.0.tar.gz
Size 4.9 kB
Tags Source
SHA-256 checksum
How to use checksums
0d80bf04c8672fb5891e3b52384c65221ec38257e78fca8370cbd6a431828f4a
BLAKE2b-256 checksum
How to use checksums
8d2f2b0cdcbd8684b1e66c72a10702dc956dd0b18842625b958c4b18761d4817
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.2

Release files / auth_proxy_jwt-0.2.0-py3-none-any.whl

Download URL auth_proxy_jwt-0.2.0-py3-none-any.whl
Size 5.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7fdb06b00f3df4b1477eb217e112b4c273fee3caf643e749d69afc25444f6f3a
BLAKE2b-256 checksum
How to use checksums
5823ac7c2030d5b896e08c02c0bbc95fbdf88b6dd4d213c5fe368f8516917772
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.2

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page