---
title: Charmhub | Deploy jwt-integrator using Charmhub - The Open Operator Collection
description: Deploy the latest version of jwt-integrator on any cloud.
url: https://charmhub.io/jwt-integrator/configurations
---

# jwt-integrator

[Canonical](https://charmhub.io/publisher/data-platform "View all packages from Canonical")

* [Canonical](https://charmhub.io/publisher/data-platform "View all packages from Canonical")

Platform:

24.04

1/edge 16

```
juju deploy jwt-integrator --channel 1/edge
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [jwt-clock-skew-tolerance](https://charmhub.io/jwt-integrator/configurations#jwt-clock-skew-tolerance)
* [jwt-header](https://charmhub.io/jwt-integrator/configurations#jwt-header)
* [jwt-url-parameter](https://charmhub.io/jwt-integrator/configurations#jwt-url-parameter)
* [required-audience](https://charmhub.io/jwt-integrator/configurations#required-audience)
* [required-issuer](https://charmhub.io/jwt-integrator/configurations#required-issuer)
* [roles-key](https://charmhub.io/jwt-integrator/configurations#roles-key)
* [signing-key](https://charmhub.io/jwt-integrator/configurations#signing-key)
* [subject-key](https://charmhub.io/jwt-integrator/configurations#subject-key)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* jwt-clock-skew-tolerance | int

  Time in seconds that is tolerated as disparity between the authentication
  parties, preventing authentication failures due to the misalignment.
* jwt-header | string

  The HTTP header in which the token is transmitted. This is typically the
  Authorization header.
* jwt-url-parameter | string

  If the token is not transmitted in the HTTP header but rather as an URL
  parameter, this option defines the name of the URL parameter used.
* required-audience | string

  The name of the audience that the JWT must specify.
* required-issuer | string

  The target issuer of JWT stored in the JSON payload.
* roles-key | string

  The key in the JSON payload that stores the user’s roles.
* signing-key | secret

  The signing key(s) used to verify the token. Multiple keys can be used
  in a comma-separated list or enumerated keys.
* subject-key | string

  The key in the JSON payload that stores the username.
