3 ms·
It should be signed by the STS - which is trusted by all the downstream microservices. The STS, who validates the access_token, in the response can send back th
by prabaths 9y ago
It should be signed by the STS - which is trusted by all the downstream microservices. The STS, who validates the access_token, in the response can send back this signed JWT to the gateway. The STS of the access_token and this JWT can be the same or two different ones, based on the use case...
- hiimcharlies 9y agoThank you! I'll ask some more questions tommorow after I sleep on it if you don't mind.