---
title: PingAmStatelessAccessTokenResolver
description: Configure a PingAmStatelessAccessTokenResolver to locally resolve and validate stateless access tokens issued by PingAM, without contacting PingAM
component: pinggateway
version: 2026
page_id: pinggateway:reference:PingAmStatelessAccessTokenResolver
canonical_url: https://docs.pingidentity.com/pinggateway/2026/reference/PingAmStatelessAccessTokenResolver.html
llms_txt: https://docs.pingidentity.com/pinggateway/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2026-09-15T08:44:10Z
section_ids:
  usage: Usage
  properties: Properties
  example: Example
  more_information: More information
---

# PingAmStatelessAccessTokenResolver

Locally resolve and validate stateless access tokens issued by PingAM without referring to PingAM.

PingAM can secure access tokens by signing or encrypting them. Configure a PingAmStatelessAccessTokenResolver for signature or encryption according to the AM configuration.

This feature requires PingGateway 2026.9 or later.

## Usage

Use this resolver with the `"accessTokenResolver"` property of an [OAuth2ResourceServerFilter](OAuth2ResourceServerFilter.html).

```none
"accessTokenResolver": {
  "type": "PingAmStatelessAccessTokenResolver",
  "config": {
    "issuer": configuration expression<string>,
    "secretsProvider": SecretsProvider reference,
    "verificationSecretId": configuration expression<secret-id>, // Use "verificationSecretId" or
    "decryptionSecretId": configuration expression<secret-id>,   // "decryptionSecretId", but not both
    "skewAllowance": configuration expression<duration>
  }
}
```

## Properties

* `"issuer"`: *configuration expression<[string](preface.html#definition-string)>, required*

  URI of the AM server responsible for issuing access tokens.

* `"secretsProvider"`: *SecretsProvider [reference](preface.html#definition-reference), required*

  The [SecretsProvider](SecretsProvider.html) to query for passwords and cryptographic keys.

* `"verificationSecretId"`: *configuration expression<[secret-id](preface.html#definition-secretid)>, required if AM secures access tokens with a signature*

  The secret ID for the secret to verify the signature of signed access tokens. This must reference a [CryptoKey](../security-guide/keys.html#secret-types).

  Depending on the type of secret store, use the following values:

  * For a [JwkSetSecretStore](JwkSetSecretStore.html), use any non-empty string that conforms to the field convention for [secret-id](preface.html#definition-secretid). The value of the string isn't used.

  * For other types of secret stores:

    * `null`: No signature verification is required.

    * A `kid` as a string: Signature verification is required with the provided `kid`. The PingAmStatelessAccessTokenResolver searches for the matching `kid` in the SecretsProvider.

  Learn more about how PingGateway validates signatures in [Validate the signature of signed tokens](../security-guide/keys.html#secret-valid-signature). Learn how each type of secret store resolves named secrets in [Secrets](secrets.html).

  Use either `"verificationSecretId"` or `"decryptionSecretId"` depending on the PingAM token provider configuration. When AM signs **and** encrypts tokens, encryption takes precedence over signing.

* `"decryptionSecretId"`: *configuration expression<[secret-id](preface.html#definition-secretid)>, required if AM secures access tokens with encryption*

  The secret ID for the secret used to decrypt the JWT for confidentiality. This must reference a [CryptoKey](../security-guide/keys.html#secret-types).

  Use either `"verificationSecretId"` or `"decryptionSecretId"` depending on the PingAM token provider configuration. When AM signs **and** encrypts tokens, encryption takes precedence over signing.

- `"skewAllowance"`: *configuration expression<[duration](preface.html#definition-duration)>, optional*

  The duration to add to the validity period of a JWT to allow for clock skew between different servers.

  A `skewAllowance` of 2 minutes affects the validity period as follows:

  * A JWT with an `iat` of 12:00 is valid from 11:58 on the PingGateway clock.

  * A JWT with an `exp` 13:00 is expired after 13:02 on the PingGateway clock.

  Default: To support a zero-trust policy, the skew allowance is by default `zero`.

## Example

Find examples using this a PingAmStatelessAccessTokenResolver to resolve signed and encrypted access tokens in [Validating PingAM stateless access tokens](../gateway-guide/oauth2-rs-stateless.html).

## More information

* [OAuth2ResourceServerFilter](OAuth2ResourceServerFilter.html)

* [org.forgerock.openig.filter.oauth2.PingAmStatelessAccessTokenResolverHeaplet](../_attachments/apidocs/org/forgerock/openig/filter/oauth2/PingAmStatelessAccessTokenResolverHeaplet.html)
