Record

validation-options

Optional validations that are applied after decoding a JWT.

All time validation happens on UTC timestamps as seconds.

record validation-options {
  required-spec-claims: option​<required-claims>,
  leeway: option​<u64>,
  reject-tokens-expiring-in-less-than: option​<u64>,
  validate-exp: option​<bool>,
  validate-nbf: option​<bool>,
  sub: option​<string>,
  algorithms: option​<list​<algorithm>>,
}

Fields

NameTypeDescription
required-spec-claimsoption​<required-claims>

Which claims are required to be present before starting the validation. This does not interact with the various validate_*. If you remove exp from that list, you still need to set validate_exp to false. The only value that will be used are "exp", "nbf", "aud", "iss", "sub". Anything else will be ignored.

Defaults to {"exp"}

leewayoption​<u64>

Add some leeway (in seconds) to the exp and nbf validation to account for clock skew.

Defaults to 60.

reject-tokens-expiring-in-less-thanoption​<u64>

Reject a token some time (in seconds) before the exp to prevent expiration in transit over the network.

The value is the inverse of leeway, subtracting from the validation time.

Defaults to 0.

validate-expoption​<bool>

Whether to validate the exp field.

It will return an error if the time in the exp field is past.

Defaults to true.

validate-nbfoption​<bool>

Whether to validate the nbf field.

It will return an error if the current timestamp is before the time in the nbf field.

Validation only happens if nbf claim is present in the token. Adding nbf to required_spec_claims will make it required.

Defaults to false.

suboption​<string>

If it contains a value, the validation will check that the sub field is the same as the one provided and will error otherwise.

Validation only happens if sub claim is present in the token. Adding sub to required_spec_claims will make it required.

Defaults to None.

algorithmsoption​<list​<algorithm>>

The validation will check that the alg of the header is contained in the ones provided and will error otherwise. Will error if it is empty.

Defaults to HMAC using SHA-256