Jennifer88huang commented on a change in pull request #5201: [Issue 5050][Docs] Adjust the content structure of the security chapter URL: https://github.com/apache/pulsar/pull/5201#discussion_r325051095
########## File path: site2/docs/security-jwt.md ########## @@ -0,0 +1,243 @@ +--- +id: security-jwt +title: Client authentication using tokens based on JSON Web Tokens +sidebar_label: Authentication using JWT +--- + +## Token authentication overview + +Pulsar supports authenticating clients using security tokens that are based on +[JSON Web Tokens](https://jwt.io/introduction/) ([RFC-7519](https://tools.ietf.org/html/rfc7519)). + +You can use tokens to identify a Pulsar client and associate with some "principal" (or "role") that +is permitted to do some actions (eg: publish to a topic or consume from a topic). + +A user typically gets a user a token string from the administrator (or some automated service). + +The compact representation of a signed JWT is a string that looks like as the follwing: + +``` +eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJKb2UifQ.ipevRNuRP6HflG8cFKnmUPtypruRC4fb1DWtoLL62SY +``` + +Application specifies the token when you create the client instance. An alternative is to pass a "token supplier" (a function that returns the token when the client library needs one). + +> #### Always use TLS transport encryption +> Sending a token is equivalent to sending a password over the wire.You had better use TLS encryption all the time when you talk to the Pulsar service. See Review comment: ```suggestion > Sending a token is equivalent to sending a password over the wire. You had better use TLS encryption all the time when you talk to the Pulsar service. See ``` ---------------------------------------------------------------- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. For queries about this service, please contact Infrastructure at: us...@infra.apache.org With regards, Apache Git Services