---
title: PingFederateStatelessAccessTokenResolver
description: Configure a PingFederateStatelessAccessTokenResolver to locally resolve and validate JWT access tokens issued by PingFederate, without contacting PingFederate
component: pinggateway
version: 2026
page_id: pinggateway:reference:PingFederateStatelessAccessTokenResolver
canonical_url: https://docs.pingidentity.com/pinggateway/2026/reference/PingFederateStatelessAccessTokenResolver.html
llms_txt: https://docs.pingidentity.com/pinggateway/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2026-09-22T11:45:40Z
section_ids:
  usage: Usage
  properties: Properties
  example: Example
  more_information: More information
---

# PingFederateStatelessAccessTokenResolver

Locally resolve and validate JSON Web Token (JWT) access tokens issued by PingFederate without referring to PingFederate.

This feature requires PingGateway 2026.9 or later.

|   |                                                                     |
| - | ------------------------------------------------------------------- |
|   | This access token resolver doesn't support encrypted access tokens. |

## Usage

Use this resolver with the `"accessTokenResolver"` property of an [OAuth2ResourceServerFilter](OAuth2ResourceServerFilter.html).

```none
"accessTokenResolver": {
  "type": "PingFederateStatelessAccessTokenResolver",
  "config": {
    "pingFederateService": PingFederateService reference,
    "iss": configuration expression<string>,
    "aud": [ configuration expression<string>, ... ],
    "skewAllowance": configuration expression<duration>,
    "scope": {
      "claim": configuration expression<string>,
      "format": configuration expression<string>
    }
  }
}
```

## Properties

* `"pingFederateService"`: *PingFederateService [reference](preface.html#definition-reference), required*

  The [PingFederateService](PingFederateService.html) declared in the heap that exposes the PingFederate JSON Web Key (JWK) set.

* `"iss"`: *configuration expression<[string](preface.html#definition-string)>, optional*

  Issuer claim to enforce.

  When empty or not set, PingGateway doesn't check the issuer.

  Default: Not set

* `"aud"`: *configuration expression<[string](preface.html#definition-string)>, optional*

  Audience claim(s) to enforce.

  A string or array of strings to match the token's audience claim.

  When empty or not set, PingGateway doesn't check the audience.

  Default: Not set

- `"skewAllowance"`: *configuration expression<[duration](preface.html#definition-duration)>, optional*

  The duration to add to the validity period of a JWT to allow for clock skew between different servers.

  A `skewAllowance` of 2 minutes affects the validity period as follows:

  * A JWT with an `iat` of 12:00 is valid from 11:58 on the PingGateway clock.

  * A JWT with an `exp` 13:00 is expired after 13:02 on the PingGateway clock.

  Default: To support a zero-trust policy, the skew allowance is by default `zero`.

- `"scope"`: *configuration expression<[object](preface.html#definition-object)>, optional*

  Scope claim configuration.

  * `"claim"`: *configuration expression<[string](preface.html#definition-string)>, optional*

    The claim holding the scopes.

    Default: `"scope"`

  * `"format"`: *configuration expression<[string](preface.html#definition-string)>, optional*

    How the scopes are encoded in the claim. One of:

    * `"json-array"`

    * `"space-delimited"`

  Default: `"space-delimited"`

## Example

This example shows an access token resolver configuration for tokens with the audience `my-client-id`:

```json
{
    "name": "PingFederateResolver",
    "type": "PingFederateStatelessAccessTokenResolver",
    "config": {
        "pingFederateService": "PingFederateService",
        "iss": "https://pingfed.example.com",
        "aud": "my-client-id",
        "skewAllowance": "1 minute",
        "scope": {
            "claim": "scope",
            "format": "space-delimited"
        }
    }
}
```

## More information

* [OAuth2ResourceServerFilter](OAuth2ResourceServerFilter.html)

* [org.forgerock.openig.ping.PingFederateStatelessAccessTokenResolverHeaplet](../_attachments/apidocs/org/forgerock/openig/ping/PingFederateStatelessAccessTokenResolverHeaplet.html)
