PageSourceSearch

https://openbao.org/assets/js/170a1593.cd2bd353.js

js openbao.org collected 2026-10-02 06:33:48 UTC 4,340 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkwebsite=self.webpackChunkwebsite||[]).push([["12625"],{61993(e,t,n){n.r(t),n.d(t,{metadata:()=>o,default:()=>c,frontMatter:()=>d,contentTitle:()=>i,toc:()=>h,assets:()=>a});var o=JSON.parse('{"id":"agent-and-proxy/autoauth/methods/jwt","title":"OpenBao Auto-Auth JWT method","description":"JWT Method for OpenBao Auto-Auth","source":"@site/versioned_docs/version-2.6.x/agent-and-proxy/autoauth/methods/jwt.mdx","sourceDirName":"agent-and-proxy/autoauth/methods","slug":"/agent-and-proxy/autoauth/methods/jwt","permalink":"/docs/2.6.x/agent-and-proxy/autoauth/methods/jwt","draft":false,"unlisted":false,"editUrl":"https://github.com/openbao/openbao/blob/release/2.6.x/website/content/docs/agent-and-proxy/autoauth/methods/jwt.mdx","tags":[],"version":"2.6.x","frontMatter":{"sidebar_label":"JWT","description":"JWT Method for OpenBao Auto-Auth"},"sidebar":"docs","previous":{"title":"Cert","permalink":"/docs/2.6.x/agent-and-proxy/autoauth/methods/cert"},"next":{"title":"Kerberos","permalink":"/docs/2.6.x/agent-and-proxy/autoauth/methods/kerberos"}}'),r=n(94686),s=n(44812);let d={sidebar_label:"JWT",description:"JWT Method for OpenBao Auto-Auth"},i="OpenBao Auto-Auth JWT method",a={},h=[{value:"Configuration",id:"configuration",level:2}];function l(e){let t={a:"a",code:"code",h1:"h1",h2:"h2",header:"header",li:"li",p:"p",ul:"ul",...(0,s.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(t.header,{children:(0,r.jsx)(t.h1,{id:"openbao-auto-auth-jwt-method",children:"OpenBao Auto-Auth JWT method"})}),"\n",(0,r.jsxs)(t.p,{children:["The ",(0,r.jsx)(t.code,{children:"jwt"})," method reads in a JWT from a file and sends it to the ",(0,r.jsx)(t.a,{href:"/docs/2.6.x/auth/jwt/",children:"JWT Auth\nmethod"}),"."]}),"\n",(0,r.jsx)(t.h2,{id:"configuration",children:"Configuration"}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsxs)(t.li,{children:["\n",(0,r.jsxs)(t.p,{children:[(0,r.jsx)(t.code,{children:"path"})," ",(0,r.jsx)(t.code,{children:"(string: required)"})," - The path to the JWT file"]}),"\n"]}),"\n",(0,r.jsxs)(t.li,{children:["\n",(0,r.jsxs)(t.p,{children:[(0,r.jsx)(t.code,{children:"role"})," ",(0,r.jsx)(t.code,{children:"(string: required)"})," - The role to authenticate against on OpenBao"]}),"\n"]}),"\n",(0,r.jsxs)(t.li,{children:["\n",(0,r.jsxs)(t.p,{children:[(0,r.jsx)(t.code,{children:"remove_jwt_after_reading"})," ",(0,r.jsx)(t.code,{children:"(bool: optional, defaults to true)"})," -\nThis can be set to ",(0,r.jsx)(t.code,{children:"false"})," to disable the default behavior of removing the\nJWT after it's been read."]}),"\n"]}),"\n",(0,r.jsxs)(t.li,{children:["\n",(0,r.jsxs)(t.p,{children:[(0,r.jsx)(t.code,{children:"remove_jwt_follows_symlinks"})," ",(0,r.jsx)(t.code,{children:"(bool: optional, defaults to false)"})," -\nThis can be set to ",(0,r.jsx)(t.code,{children:"true"})," to follow symlinks when removing the JWT after it has been read\nwhen executing the ",(0,r.jsx)(t.code,{children:"remove_jwt_after_reading"})," behaviour. If set to false, it will delete\nthe symlink, not the JWT. Does nothing if ",(0,r.jsx)(t.code,{children:"remove_jwt_after_reading"})," is false."]}),"\n"]}),"\n",(0,r.jsxs)(t.li,{children:["\n",(0,r.jsxs)(t.p,{children:[(0,r.jsx)(t.code,{children:"jwt_read_period"})," ",(0,r.jsx)(t.code,{children:'(duration: "0.5s", optional)'})," - The duration after which\nAgent will attempt to read the JWT stored at ",(0,r.jsx)(t.code,{children:"path"}),". Defaults to ",(0,r.jsx)(t.code,{children:"1m"})," if\n",(0,r.jsx)(t.code,{children:"remove_jwt_after_reading"})," is set to ",(0,r.jsx)(t.code,{children:"true"}),", or ",(0,r.jsx)(t.code,{children:"0.5s"})," otherwise.\nUses ",(0,r.jsx)(t.a,{href:"/docs/2.6.x/concepts/duration-format",children:"duration format strings"}),"."]}),"\n"]}),"\n"]})]})}function c(e={}){let{wrapper:t}={...(0,s.R)(),...e.components};return t?(0,r.jsx)(t,{...e,children:(0,r.jsx)(l,{...e})}):l(e)}},44812(e,t,n){n.d(t,{R:()=>d,x:()=>i});var o=n(92990);let r={},s=o.createContext(r);function d(e){let t=o.useContext(s);return o.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function i(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:d(e.components),o.createElement(s.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.