PingGateway

PingFederateStatelessAccessTokenResolver

Locally resolve and validate JSON Web Token (JWT) access tokens issued by PingFederate without referring to PingFederate.

This feature requires PingGateway 2026.9 or later.

This access token resolver doesn’t support encrypted access tokens.

Usage

Use this resolver with the "accessTokenResolver" property of an OAuth2ResourceServerFilter.

"accessTokenResolver": {
  "type": "PingFederateStatelessAccessTokenResolver",
  "config": {
    "pingFederateService": PingFederateService reference,
    "iss": configuration expression<string>,
    "aud": [ configuration expression<string>, ... ],
    "skewAllowance": configuration expression<duration>,
    "scope": {
      "claim": configuration expression<string>,
      "format": configuration expression<string>
    }
  }
}

Properties

"pingFederateService": PingFederateService reference, required

The PingFederateService declared in the heap that exposes the PingFederate JSON Web Key (JWK) set.

"iss": configuration expression<string>, optional

Issuer claim to enforce.

When empty or not set, PingGateway doesn’t check the issuer.

Default: Not set

"aud": configuration expression<string>, optional

Audience claim(s) to enforce.

A string or array of strings to match the token’s audience claim.

When empty or not set, PingGateway doesn’t check the audience.

Default: Not set

"skewAllowance": configuration expression<duration>, optional

The duration to add to the validity period of a JWT to allow for clock skew between different servers.

A skewAllowance of 2 minutes affects the validity period as follows:

  • A JWT with an iat of 12:00 is valid from 11:58 on the PingGateway clock.

  • A JWT with an exp 13:00 is expired after 13:02 on the PingGateway clock.

Default: To support a zero-trust policy, the skew allowance is by default zero.

"scope": configuration expression<object>, optional

Scope claim configuration.

"claim": configuration expression<string>, optional

The claim holding the scopes.

Default: "scope"

"format": configuration expression<string>, optional

How the scopes are encoded in the claim. One of:

  • "json-array"

  • "space-delimited"

Default: "space-delimited"

Example

This example shows an access token resolver configuration for tokens with the audience my-client-id:

{
    "name": "PingFederateResolver",
    "type": "PingFederateStatelessAccessTokenResolver",
    "config": {
        "pingFederateService": "PingFederateService",
        "iss": "https://pingfed.example.com",
        "aud": "my-client-id",
        "skewAllowance": "1 minute",
        "scope": {
            "claim": "scope",
            "format": "space-delimited"
        }
    }
}