PingGateway

PingAmStatelessAccessTokenResolver

Locally resolve and validate stateless access tokens issued by PingAM without referring to PingAM.

PingAM can secure access tokens by signing or encrypting them. Configure a PingAmStatelessAccessTokenResolver for signature or encryption according to the AM configuration.

This feature requires PingGateway 2026.9 or later.

Usage

Use this resolver with the "accessTokenResolver" property of an OAuth2ResourceServerFilter.

"accessTokenResolver": {
  "type": "PingAmStatelessAccessTokenResolver",
  "config": {
    "issuer": configuration expression<string>,
    "secretsProvider": SecretsProvider reference,
    "verificationSecretId": configuration expression<secret-id>, // Use "verificationSecretId" or
    "decryptionSecretId": configuration expression<secret-id>,   // "decryptionSecretId", but not both
    "skewAllowance": configuration expression<duration>
  }
}

Properties

"issuer": configuration expression<string>, required

URI of the AM server responsible for issuing access tokens.

"secretsProvider": SecretsProvider reference, required

The SecretsProvider to query for passwords and cryptographic keys.

"verificationSecretId": configuration expression<secret-id>, required if AM secures access tokens with a signature

The secret ID for the secret to verify the signature of signed access tokens. This must reference a CryptoKey.

Depending on the type of secret store, use the following values:

  • For a JwkSetSecretStore, use any non-empty string that conforms to the field convention for secret-id. The value of the string isn’t used.

  • For other types of secret stores:

    • null: No signature verification is required.

    • A kid as a string: Signature verification is required with the provided kid. The PingAmStatelessAccessTokenResolver searches for the matching kid in the SecretsProvider.

Learn more about how PingGateway validates signatures in Validate the signature of signed tokens. Learn how each type of secret store resolves named secrets in Secrets.

Use either "verificationSecretId" or "decryptionSecretId" depending on the PingAM token provider configuration. When AM signs and encrypts tokens, encryption takes precedence over signing.

"decryptionSecretId": configuration expression<secret-id>, required if AM secures access tokens with encryption

The secret ID for the secret used to decrypt the JWT for confidentiality. This must reference a CryptoKey.

Use either "verificationSecretId" or "decryptionSecretId" depending on the PingAM token provider configuration. When AM signs and encrypts tokens, encryption takes precedence over signing.

"skewAllowance": configuration expression<duration>, optional

The duration to add to the validity period of a JWT to allow for clock skew between different servers.

A skewAllowance of 2 minutes affects the validity period as follows:

  • A JWT with an iat of 12:00 is valid from 11:58 on the PingGateway clock.

  • A JWT with an exp 13:00 is expired after 13:02 on the PingGateway clock.

Default: To support a zero-trust policy, the skew allowance is by default zero.

Example

Find examples using this a PingAmStatelessAccessTokenResolver to resolve signed and encrypted access tokens in Validating PingAM stateless access tokens.