{"repo":"traefik-plugins/traefik-jwt-plugin","free":true,"listed":false,"github":"https://github.com/traefik-plugins/traefik-jwt-plugin","clone":"git clone https://github.com/traefik-plugins/traefik-jwt-plugin.git","description":"Traefik plugin which checks JWT tokens for required fields. Supports Open Policy Agent (OPA) and signature validation with JWKS","language":"Go","stars":139,"topics":["traefik-plugin","jwt","opa","open-policy-agent"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"traefik-jwt-plugin [!IMPORTANT] This project is looking for maintainers. Please comment in this issue Traefik plugin for verifying JSON Web Tokens (JWT). Supports public keys, certificates or JWKS endpoints. Supports RSA, ECDSA and symmetric keys. Supports Open Policy Agent (OPA) for additional authorization checks. Features: RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384, ES512, HS256, HS384, HS512 Certificates or public keys can be configured in the dynamic config Supports JWK endpoints for fetching keys remotely Reject a request or Log warning when required field is missing from JWT payload Validate request with Open Policy Agent Adds the verified and decoded token to the OPA input Installation The plugin needs to be configured in the Traefik static configuration before it can be used. Kubernetes Tested with official Traefik chart version 26.0.0. The following snippet should be added to values.yaml : Command line Configuration The plugin currently supports the following configuration settings: (all fields are optional) Name Description ---- ---- OpaUrl URL of OPA policy document requested for decision, e.g. http://opa:8181/v1/data/example. OpaAllowField Field in the JSON result which contains a boolean, indicating whether the request is allowed or not. Default allow . OpaBody Boolean indicating whether the request body should be added to the OPA input. OpaDebugMode Set the opa response in the http response body when the request isn't allowed otherwise the response ","default_branch":null,"files":null,"tree":[],"storefront":"/r/traefik-plugins","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/traefik-plugins/traefik-jwt-plugin/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}