Hey community 👋
We just published a
technical guide on how to leverage JWT claims in Cerbos.
Feel free to check it out if it’s relevant for you.
Main takeaways:
• Cerbos verifies JWTs using your JWKS and exposes claims directly to policy conditions.
• You can configure multiple keysets, cache verified tokens, and handle rotation without restarts.
• Claims like iss, aud, and sub can be enforced centrally in CEL expressions.
• Gateways can pass tokens through; one policy set covers edge and service.
• Stolen credentials remain a top initial action in breaches at 24 percent in 2024. Strong token verification helps reduce risk.
• Disable verification only for controlled testing, not for production.