PingFederateStatelessAccessTokenResolver
Locally resolve and validate JSON Web Token (JWT) access tokens issued by PingFederate without referring to PingFederate.
This feature requires PingGateway 2026.9 or later.
| This access token resolver doesn’t support encrypted access tokens. |
Usage
Use this resolver with the "accessTokenResolver" property of an OAuth2ResourceServerFilter.
"accessTokenResolver": {
"type": "PingFederateStatelessAccessTokenResolver",
"config": {
"pingFederateService": PingFederateService reference,
"iss": configuration expression<string>,
"aud": [ configuration expression<string>, ... ],
"skewAllowance": configuration expression<duration>,
"scope": {
"claim": configuration expression<string>,
"format": configuration expression<string>
}
}
}
Properties
"pingFederateService": PingFederateService reference, required-
The PingFederateService declared in the heap that exposes the PingFederate JSON Web Key (JWK) set.
"iss": configuration expression<string>, optional-
Issuer claim to enforce.
When empty or not set, PingGateway doesn’t check the issuer.
Default: Not set
"aud": configuration expression<string>, optional-
Audience claim(s) to enforce.
A string or array of strings to match the token’s audience claim.
When empty or not set, PingGateway doesn’t check the audience.
Default: Not set
"skewAllowance": configuration expression<duration>, optional-
The duration to add to the validity period of a JWT to allow for clock skew between different servers.
A
skewAllowanceof 2 minutes affects the validity period as follows:-
A JWT with an
iatof 12:00 is valid from 11:58 on the PingGateway clock. -
A JWT with an
exp13:00 is expired after 13:02 on the PingGateway clock.
Default: To support a zero-trust policy, the skew allowance is by default
zero. -
"scope": configuration expression<object>, optional-
Scope claim configuration.
Default:
"space-delimited"
Example
This example shows an access token resolver configuration for tokens with the audience my-client-id:
{
"name": "PingFederateResolver",
"type": "PingFederateStatelessAccessTokenResolver",
"config": {
"pingFederateService": "PingFederateService",
"iss": "https://pingfed.example.com",
"aud": "my-client-id",
"skewAllowance": "1 minute",
"scope": {
"claim": "scope",
"format": "space-delimited"
}
}
}