Skip to content

Get Signed JWT

The task uses the RS256 algorithm to sign the JWT. The signed token includes the specified authorization scopes and an expiration time based on the configured TTL (time-to-live).

Task parameters

Configure these parameters for the Get Signed JWT task.

Parameter Description Required/ Optional
inputParameters. subject The subject of the JWT, typically representing the entity (e.g., user or service) for which the token is issued. Required.
inputParameters. issuer The entity issuing the JWT, identifying who created and signed the token. Required.
inputParameters. privateKey The RSA private key used to sign the JWT, in PKCS#8 format. The BEGIN PRIVATE KEY and END PRIVATE KEY lines are optional. Required.
inputParameters. privateKeyId The identifier of the private key used to sign the JWT. It is added to the JWT header as kid. Required.
inputParameters. audience The intended recipient of the JWT. Required.
inputParameters. ttlInSecond The time-to-live (TTL) of the JWT, in seconds. The JWT expires this many seconds after it is created. Required.
inputParameters. scopes The scopes granted by the JWT, as an array of strings. They are added to the JWT as a single space-separated scope claim. Required.
inputParameters. algorithm The signing algorithm. Only RS256 (RSA signature with SHA-256) is supported. If not set, RS256 is used. Optional.

The following are generic configuration parameters that can be applied to the task and are not specific to the Get Signed JWT task.

Caching parameters

You can cache the task outputs using the following parameters. Refer to Caching Task Outputs for a full guide.

Parameter Description Required/ Optional
cacheConfig.ttlInSecond The time to live in seconds, which is the duration for the output to be cached. Required if using cacheConfig.
cacheConfig.key The cache key is a unique identifier for the cached output and must be constructed exclusively from the task’s input parameters.
It can be a string concatenation that contains the task’s input keys, such as ${uri}-${method} or re_${uri}_${method}.
Required if using cacheConfig.
Other generic parameters

Here are other parameters for configuring the task behavior.

Parameter Description Required/ Optional
optional Whether the task is optional.

If set to true, any task failure is ignored, and the workflow continues with the task status updated to COMPLETED_WITH_ERRORS. However, the task must reach a terminal state. If the task remains incomplete, the workflow waits until it reaches a terminal state before proceeding.
Optional.

Task configuration

This is the task configuration for a Get Signed JWT task.

{
     "name": "get_signed_jwt",
     "taskReferenceName": "get_signed_jwt_ref",
     "inputParameters": {
       "subject": "${workflow.input.subject}",
       "issuer": "${workflow.input.issuer}",
       "privateKey": "${workflow.secrets.jwt-privatekey}",
       "privateKeyId": "key-123",
       "audience": "${workflow.input.audience}",
       "ttlInSecond": 3600,
       "scopes": "${workflow.input.scope}",
       "algorithm": "RS256"
     },
     "type": "GET_SIGNED_JWT"
}

Task output

The Get Signed JWT task returns the signed JWT in the _secrets variable. The signed JWT will be masked (***). To use the JWT in a later task, reference ${<taskReferenceName>.output._secrets.jwt}.

Examples

Here are some examples for using the Get Signed JWT task.

Authorization

In this example, the Get Signed JWT is used for server-to-server interaction between Conductor and Google. The signed JWT can be subsequently used to request an access token for calling the Google API.

{
  "name": "get_signed_jwt_token",
  "taskReferenceName": "get_signed_jwt_token_ref",
  "inputParameters": {
    "privateKey": "${workflow.secrets.gcp_private_key}",
    "privateKeyId": "${workflow.secrets.gcp_private_key_id}",
    "audience": "https://oauth2.googleapis.com/token",
    "ttlInSecond": 3600,
    "scopes": [
      "https://www.googleapis.com/auth/cloud-platform",
      "https://www.googleapis.com/auth/documents",
      "https://www.googleapis.com/auth/drive"
    ],
    "subject": "service-account-name@project-id.iam.gserviceaccount.com",
    "issuer": "service-account-name@project-id.iam.gserviceaccount.com"
  },
  "type": "GET_SIGNED_JWT"
}