Class JwtTokenProvider

java.lang.Object
io.openlineage.client.transports.TokenEndpointTokenProvider
io.openlineage.client.transports.JwtTokenProvider
All Implemented Interfaces:
TokenProvider

public class JwtTokenProvider extends TokenEndpointTokenProvider
TokenProvider that exchanges an API key for a JWT token via a POST endpoint.

Sends the API key and OAuth parameters as URL-encoded form data.

The provider automatically tries multiple common JSON field names for the token: the configured tokenFields (default ["token", "access_token"]). This ensures compatibility with various OAuth providers.

The provider caches tokens and automatically refreshes them before expiry. By default, tokens are refreshed 120 seconds before they expire. This can be configured using the tokenRefreshBuffer parameter.

Configuration example:


 transport:
   type: http
   url: https://api.example.com
   auth:
     type: jwt
     apiKey: your-api-key
     tokenEndpoint: https://auth.example.com/token
     tokenFields: ["token", "access_token"]  # optional, defaults to ["token", "access_token"]
     expiresInField: expires_in  # optional, defaults to "expires_in"
     grantType: urn:ietf:params:oauth:grant-type:jwt-bearer  # optional, defaults to "urn:ietf:params:oauth:grant-type:jwt-bearer"
     responseType: token  # optional, defaults to "token"
     tokenRefreshBuffer: 120  # optional, defaults to 120 seconds
 

For IBM Cloud IAM, use these settings:


 auth:
   type: jwt
   apiKey: your-ibm-api-key
   tokenEndpoint: https://iam.cloud.ibm.com/identity/token
   grantType: urn:ibm:params:oauth:grant-type:apikey
   responseType: cloud_iam
 
  • Constructor Details

    • JwtTokenProvider

      public JwtTokenProvider(String apiKey, URI tokenEndpoint)
      Constructor that requires mandatory parameters apiKey and tokenEndpoint. Used by Jackson for deserialization.
      Parameters:
      apiKey - The API key for authentication (required)
      tokenEndpoint - The token endpoint URI (required)
      Throws:
      IllegalArgumentException - if apiKey is null/empty or tokenEndpoint is null
  • Method Details

    • getTokenName

      protected String getTokenName()
      Description copied from class: TokenEndpointTokenProvider
      Name of the token used in log and error messages, for example "JWT token".
      Specified by:
      getTokenName in class TokenEndpointTokenProvider
    • getTokenRequestParameters

      protected List<org.apache.hc.core5.http.NameValuePair> getTokenRequestParameters()
      Description copied from class: TokenEndpointTokenProvider
      URL-encoded form parameters sent to the token endpoint.
      Specified by:
      getTokenRequestParameters in class TokenEndpointTokenProvider
    • toString

      public String toString()
      Overrides:
      toString in class TokenEndpointTokenProvider
    • getApiKey

      public String getApiKey()
    • getGrantType

      public String getGrantType()
      OAuth grant type parameter sent in the token request. Optional, default: "urn:ietf:params:oauth:grant-type:jwt-bearer"
    • setGrantType

      public void setGrantType(String grantType)
      OAuth grant type parameter sent in the token request. Optional, default: "urn:ietf:params:oauth:grant-type:jwt-bearer"
    • getResponseType

      public String getResponseType()
      OAuth response type parameter sent in the token request. Optional, default: "token"
    • setResponseType

      public void setResponseType(String responseType)
      OAuth response type parameter sent in the token request. Optional, default: "token"