Class JwtCredentials
- All Implemented Interfaces:
JwtProvider
,Serializable
Uses a JSON Web Token (JWT) directly in the request metadata to provide authorization.
JwtClaims claims = JwtClaims.newBuilder()
.setAudience("https://example.com/some-audience")
.setIssuer("some-issuer@example.com")
.setSubject("some-subject@example.com")
.build();
Credentials = JwtCredentials.newBuilder()
.setPrivateKey(privateKey)
.setPrivateKeyId("private-key-id")
.setJwtClaims(claims)
.build();
- See Also:
-
Nested Class Summary
Nested Classes -
Field Summary
FieldsModifier and TypeFieldDescription(package private) com.google.api.client.util.Clock
private static final long
private Long
private String
private static final String
private static final String
private final JwtClaims
private final Long
private final Object
private final PrivateKey
private final String
Fields inherited from class com.google.auth.Credentials
GOOGLE_DEFAULT_UNIVERSE
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionboolean
A constant string name describing the authentication technology.(package private) com.google.api.client.util.Clock
getClock()
getRequestMetadata
(URI uri) Get the current request metadata in a blocking manner, refreshing tokens if required.int
hashCode()
boolean
Whether the credentials have metadata entries that should be added to each request.boolean
Indicates whether or not the Auth mechanism works purely by including request metadata.jwtWithClaims
(JwtClaims newClaims) Returns a copy of these credentials with modified claims.static JwtCredentials.Builder
void
refresh()
Refresh the token by discarding the cached token and metadata and rebuilding a new one.private boolean
Methods inherited from class com.google.auth.Credentials
blockingGetToCallback, getMetricsCredentialType, getRequestMetadata, getRequestMetadata, getUniverseDomain
-
Field Details
-
JWT_ACCESS_PREFIX
- See Also:
-
JWT_INCOMPLETE_ERROR_MESSAGE
- See Also:
-
CLOCK_SKEW
private static final long CLOCK_SKEW -
lock
-
privateKey
-
privateKeyId
-
jwtClaims
-
lifeSpanSeconds
-
clock
transient com.google.api.client.util.Clock clock -
jwt
-
expiryInSeconds
-
-
Constructor Details
-
JwtCredentials
-
-
Method Details
-
newBuilder
-
refresh
Refresh the token by discarding the cached token and metadata and rebuilding a new one.- Specified by:
refresh
in classCredentials
- Throws:
IOException
- if there was an error getting up-to-date access.
-
shouldRefresh
private boolean shouldRefresh() -
jwtWithClaims
Returns a copy of these credentials with modified claims.- Specified by:
jwtWithClaims
in interfaceJwtProvider
- Parameters:
newClaims
- new claims. Any unspecified claim fields default to the the current values.- Returns:
- new credentials
-
getAuthenticationType
Description copied from class:Credentials
A constant string name describing the authentication technology.E.g. “OAuth2”, “SSL”. For use by the transport layer to determine whether it supports the type of authentication in the case where
Credentials.hasRequestMetadataOnly()
is false. Also serves as a debugging helper.- Specified by:
getAuthenticationType
in classCredentials
- Returns:
- The type of authentication used.
-
getRequestMetadata
Description copied from class:Credentials
Get the current request metadata in a blocking manner, refreshing tokens if required.This should be called by the transport layer on each request, and the data should be populated in headers or other context. The operation can block and fail to complete and may do things such as refreshing access tokens.
The convention for handling binary data is for the key in the returned map to end with
"-bin"
and for the corresponding values to be base64 encoded.- Specified by:
getRequestMetadata
in classCredentials
- Parameters:
uri
- URI of the entry point for the request.- Returns:
- The request metadata used for populating headers or other context.
- Throws:
IOException
- if there was an error getting up-to-date access. The exception should implementRetryable
andisRetryable()
will return true if the operation may be retried.
-
hasRequestMetadata
public boolean hasRequestMetadata()Description copied from class:Credentials
Whether the credentials have metadata entries that should be added to each request.This should be called by the transport layer to see if
Credentials.getRequestMetadata()
should be used for each request.- Specified by:
hasRequestMetadata
in classCredentials
- Returns:
- Whether or not the transport layer should call
Credentials.getRequestMetadata()
-
hasRequestMetadataOnly
public boolean hasRequestMetadataOnly()Description copied from class:Credentials
Indicates whether or not the Auth mechanism works purely by including request metadata.This is meant for the transport layer. If this is true a transport does not need to take actions other than including the request metadata. If this is false, a transport must specifically know about the authentication technology to support it, and should fail to accept the credentials otherwise.
- Specified by:
hasRequestMetadataOnly
in classCredentials
- Returns:
- Whether or not the Auth mechanism works purely by including request metadata.
-
equals
-
hashCode
public int hashCode() -
getClock
com.google.api.client.util.Clock getClock()
-