PingAmStatelessAccessTokenResolver
Locally resolve and validate stateless access tokens issued by PingAM without referring to PingAM.
PingAM can secure access tokens by signing or encrypting them. Configure a PingAmStatelessAccessTokenResolver for signature or encryption according to the AM configuration.
This feature requires PingGateway 2026.9 or later.
Usage
Use this resolver with the "accessTokenResolver" property of an OAuth2ResourceServerFilter.
"accessTokenResolver": {
"type": "PingAmStatelessAccessTokenResolver",
"config": {
"issuer": configuration expression<string>,
"secretsProvider": SecretsProvider reference,
"verificationSecretId": configuration expression<secret-id>, // Use "verificationSecretId" or
"decryptionSecretId": configuration expression<secret-id>, // "decryptionSecretId", but not both
"skewAllowance": configuration expression<duration>
}
}
Properties
"issuer": configuration expression<string>, required-
URI of the AM server responsible for issuing access tokens.
"secretsProvider": SecretsProvider reference, required-
The SecretsProvider to query for passwords and cryptographic keys.
"verificationSecretId": configuration expression<secret-id>, required if AM secures access tokens with a signature-
The secret ID for the secret to verify the signature of signed access tokens. This must reference a CryptoKey.
Depending on the type of secret store, use the following values:
-
For a JwkSetSecretStore, use any non-empty string that conforms to the field convention for secret-id. The value of the string isn’t used.
-
For other types of secret stores:
-
null: No signature verification is required. -
A
kidas a string: Signature verification is required with the providedkid. The PingAmStatelessAccessTokenResolver searches for the matchingkidin the SecretsProvider.
-
Learn more about how PingGateway validates signatures in Validate the signature of signed tokens. Learn how each type of secret store resolves named secrets in Secrets.
Use either
"verificationSecretId"or"decryptionSecretId"depending on the PingAM token provider configuration. When AM signs and encrypts tokens, encryption takes precedence over signing. -
"decryptionSecretId": configuration expression<secret-id>, required if AM secures access tokens with encryption-
The secret ID for the secret used to decrypt the JWT for confidentiality. This must reference a CryptoKey.
Use either
"verificationSecretId"or"decryptionSecretId"depending on the PingAM token provider configuration. When AM signs and encrypts tokens, encryption takes precedence over signing.
"skewAllowance": configuration expression<duration>, optional-
The duration to add to the validity period of a JWT to allow for clock skew between different servers.
A
skewAllowanceof 2 minutes affects the validity period as follows:-
A JWT with an
iatof 12:00 is valid from 11:58 on the PingGateway clock. -
A JWT with an
exp13:00 is expired after 13:02 on the PingGateway clock.
Default: To support a zero-trust policy, the skew allowance is by default
zero. -
Example
Find examples using this a PingAmStatelessAccessTokenResolver to resolve signed and encrypted access tokens in Validating PingAM stateless access tokens.