Package io.openlineage.client.transports
Class JwtTokenProvider
java.lang.Object
io.openlineage.client.transports.TokenEndpointTokenProvider
io.openlineage.client.transports.JwtTokenProvider
- All Implemented Interfaces:
TokenProvider
TokenProvider that exchanges an API key for a JWT token via a POST endpoint.
Sends the API key and OAuth parameters as URL-encoded form data.
The provider automatically tries multiple common JSON field names for the token: the configured tokenFields (default ["token", "access_token"]). This ensures compatibility with various OAuth providers.
The provider caches tokens and automatically refreshes them before expiry. By default, tokens are refreshed 120 seconds before they expire. This can be configured using the tokenRefreshBuffer parameter.
Configuration example:
transport:
type: http
url: https://api.example.com
auth:
type: jwt
apiKey: your-api-key
tokenEndpoint: https://auth.example.com/token
tokenFields: ["token", "access_token"] # optional, defaults to ["token", "access_token"]
expiresInField: expires_in # optional, defaults to "expires_in"
grantType: urn:ietf:params:oauth:grant-type:jwt-bearer # optional, defaults to "urn:ietf:params:oauth:grant-type:jwt-bearer"
responseType: token # optional, defaults to "token"
tokenRefreshBuffer: 120 # optional, defaults to 120 seconds
For IBM Cloud IAM, use these settings:
auth:
type: jwt
apiKey: your-ibm-api-key
tokenEndpoint: https://iam.cloud.ibm.com/identity/token
grantType: urn:ibm:params:oauth:grant-type:apikey
responseType: cloud_iam
-
Constructor Summary
ConstructorsConstructorDescriptionJwtTokenProvider(String apiKey, URI tokenEndpoint) Constructor that requires mandatory parameters apiKey and tokenEndpoint. -
Method Summary
Modifier and TypeMethodDescriptionOAuth grant type parameter sent in the token request.OAuth response type parameter sent in the token request.protected StringName of the token used in log and error messages, for example "JWT token".protected List<org.apache.hc.core5.http.NameValuePair>URL-encoded form parameters sent to the token endpoint.voidsetGrantType(String grantType) OAuth grant type parameter sent in the token request.voidsetResponseType(String responseType) OAuth response type parameter sent in the token request.toString()Methods inherited from class io.openlineage.client.transports.TokenEndpointTokenProvider
createHttpClient, getCurrentTimeSeconds, getExpiresInField, getToken, getTokenEndpoint, getTokenFields, getTokenRefreshBuffer, getTokenRequestAuthorization, setExpiresInField, setTokenFields, setTokenRefreshBuffer
-
Constructor Details
-
JwtTokenProvider
Constructor that requires mandatory parameters apiKey and tokenEndpoint. Used by Jackson for deserialization.- Parameters:
apiKey- The API key for authentication (required)tokenEndpoint- The token endpoint URI (required)- Throws:
IllegalArgumentException- if apiKey is null/empty or tokenEndpoint is null
-
-
Method Details
-
getTokenName
Description copied from class:TokenEndpointTokenProviderName of the token used in log and error messages, for example "JWT token".- Specified by:
getTokenNamein classTokenEndpointTokenProvider
-
getTokenRequestParameters
Description copied from class:TokenEndpointTokenProviderURL-encoded form parameters sent to the token endpoint.- Specified by:
getTokenRequestParametersin classTokenEndpointTokenProvider
-
toString
- Overrides:
toStringin classTokenEndpointTokenProvider
-
getApiKey
-
getGrantType
OAuth grant type parameter sent in the token request. Optional, default: "urn:ietf:params:oauth:grant-type:jwt-bearer" -
setGrantType
OAuth grant type parameter sent in the token request. Optional, default: "urn:ietf:params:oauth:grant-type:jwt-bearer" -
getResponseType
OAuth response type parameter sent in the token request. Optional, default: "token" -
setResponseType
OAuth response type parameter sent in the token request. Optional, default: "token"
-