Token validation for multiple IdPsv1.0+

You can verify tokens issued by multiple IdP using the extra_jwks_uris configuration option, with the following considerations:

  • Since the plugin only accepts a single issuer, any iss claim verification will fail for tokens that come from a different IdP than the one that was used in the issuer configuration option. Add all issuers as they appear in the iss claims of your tokens to the config.issuers_allowed setting.
  • If you make any changes to the extra_jwks_uris value, you have to clear the second level DB cache for the change to become effective. See Delete a Discovery Cache Object.

This example shows how to configure two different extra_jwks_uris to support token validation for two different IdPs.

For a complete example with Keycloak as the IdP, see the tutorial for configuring OpenID Connect with multiple IdPs using a trusted issuer registry.

Note: extra_jwks_uris adds multiple discovery endpoints, but the plugin will still look at the jwks_uri returned by the internal discovery mechanism first, introducing potential latency. If you want to override the default discovery JWKS endpoint instead of providing multiple fallback options, see the Use a custom JWKS endpoint for discovery example.

Prerequisites

  • A configured identity provider (IdP)

Environment variables

  • ISSUER: The issuer authentication URL for your IdP. For example, if you’re using Keycloak as your IdP, the issuer URL looks like this: http://localhost:8080/realms/example-realm

  • TOKEN_SALT: A random string that decK requires (v1.59 and later) so session credentials aren’t regenerated on every sync. This parameter is optional for other formats. For example, generate one with openssl rand -base64 16.

Set up the plugin

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!