Skip to content
Back to skills

Br Jwks Jwt Auth

ASecurity

Configure better-route 0.6.0 RS256/ES256 JWT verification from JWKS. Use when adding Rs256JwksJwtVerifier, JwksProviderInterface, HttpJwksProvider, StaticJwksProvider, JwtBearerTokenVerifierAdapter, strict JOSE kid matching, issuer/audience checks, JWKS transient cache, better_route/jwks_refresh, or OIDC/OAuth bearer token verification. Rejects none and HS* algorithms. Updated 2026-05-02.

  • 22 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added June 5, 2026
testinggophpgitapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned June 5, 2026

npx -y skills add Lonsdale201/wp-agent-skills --skill br-jwks-jwt-auth --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Br Jwks Jwt Auth?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Br Jwks Jwt Auth
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lonsdale201-br-jwks-jwt-auth/badge)](https://www.skillsdirectory.com/skills/lonsdale201-br-jwks-jwt-auth)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: br-jwks-jwt-auth
description: Configure better-route 0.6.0 RS256/ES256 JWT verification from JWKS. Use when adding Rs256JwksJwtVerifier, JwksProviderInterface, HttpJwksProvider, StaticJwksProvider, JwtBearerTokenVerifierAdapter, strict JOSE kid matching, issuer/audience checks, JWKS transient cache, better_route/jwks_refresh, or OIDC/OAuth bearer token verification. Rejects none and HS* algorithms. Updated 2026-05-02.
author: Soczó Kristóf
contact: mailto:lonsdale201@hotmail.com
plugin: better-route
plugin-version-tested: "0.6.0"
php-min: "8.1"
last-updated: "2026-05-02"
docs:
  - https://lonsdale201.github.io/better-docs/docs/better-route/agents
source-refs:
  - src/Middleware/Jwt/Rs256JwksJwtVerifier.php
  - src/Middleware/Jwt/JwksProviderInterface.php
  - src/Middleware/Jwt/HttpJwksProvider.php
  - src/Middleware/Jwt/StaticJwksProvider.php
  - src/Middleware/Jwt/JwksKeySanitizer.php
  - src/Middleware/Jwt/JwtVerifierInterface.php
  - src/Middleware/Auth/JwtBearerTokenVerifierAdapter.php
  - src/Middleware/Auth/BearerTokenAuthMiddleware.php
  - tests/SecurityPrimitivesTest.php
---

# better-route: JWKS JWT auth

Use this for OIDC/OAuth-style bearer JWTs signed with asymmetric keys. In better-route 0.6.0 the library ships `Rs256JwksJwtVerifier`, so do not write a custom verifier for normal `RS256` or `ES256` JWKS use cases.

## Pattern

```php
use BetterRoute\Middleware\Auth\BearerTokenAuthMiddleware;
use BetterRoute\Middleware\Auth\JwtBearerTokenVerifierAdapter;
use BetterRoute\Middleware\Jwt\HttpJwksProvider;
use BetterRoute\Middleware\Jwt\Rs256JwksJwtVerifier;

$jwks = new HttpJwksProvider(
    jwksUri: 'https://issuer.example.com/.well-known/jwks.json',
    ttlSeconds: 3600,
    issuer: 'https://issuer.example.com'
);

$verifier = new Rs256JwksJwtVerifier(
    jwks: $jwks,
    leewaySeconds: 60,
    expectedIssuer: 'https://issuer.example.com',
    expectedAudience: 'my-api',
    requireExpiration: true,
    maxLifetimeSeconds: 3600,
    allowedAlgorithms: ['RS256']
);

$auth = new BearerTokenAuthMiddleware(
    verifier: new JwtBearerTokenVerifierAdapter($verifier),
    requiredScopes: ['orders:read']
);
```

For write routes, still call `->protectedByMiddleware('bearerAuth')` so WordPress dispatches to the middleware pipeline.

## Critical rules

- `kid` in the JOSE header is required and must match exactly one usable JWKS key.
- On `kid` miss, the verifier calls `JwksProviderInterface::refresh()` once, then fails closed.
- Never fall back to "try every public key"; that accepts stale or unrelated keys.
- `allowedAlgorithms` supports `RS256` and `ES256`; `none` and `HS*` are rejected even if accidentally configured.
- `HttpJwksProvider` requires an `https` URI and uses `sslverify => true`.
- Private JWK fields are stripped by `JwksKeySanitizer`; JWKS should contain public keys only.
- Set `expectedIssuer` and `expectedAudience` in production.
- Keep `requireExpiration: true`; disabling it is a migration-only decision.

## JWKS cache invalidation

`HttpJwksProvider` listens for:

```php
do_action('better_route/jwks_refresh', 'https://issuer.example.com');
```

Use this from admin tooling after key rotation or when forcing a cache clear.

## Tests

Use `StaticJwksProvider` for unit tests:

```php
$verifier = new Rs256JwksJwtVerifier(
    new StaticJwksProvider([$publicJwk]),
    now: static fn (): int => 1700000000
);
```

## Cross-references

- Use `br-auth-middleware` for generic auth middleware choice and `protectedByMiddleware()` route intent.
- Use `br-error-contract` for the `401 invalid_token` response shape.
- Use `br-crypto` when generating nonces, state, PKCE values, or doing token-bound string compares.

Files in this skill

  • SKILL.md3.6 KB
  • agents/openai.yaml216 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…