HarperFast / HarperFast/harper

Allow users to supply their own JWT signing keys (BYOK for JWT auth)

Open
#673 0 comments 0 reactions 0 assignees View on GitHub
area:auth enhancement from-jira
Dominant language
JavaScript
Stars
89
Forks
10
Avg merge
2d 6h
Merged PRs (30d)
200

Description

Today Harper generates and manages its own JWT signing key. Operators who want to integrate with an existing identity provider or control key rotation need to supply their own keys.

## Ask

- Accept a user-supplied RSA/EC private key (and corresponding public key) via Ops API or config.
- Use the supplied key pair to sign and verify JWTs instead of Harper's auto-generated key.
- Support key rotation with a grace period for tokens signed by the previous key.

## Design considerations (Not Ready — needs decisions)

- Supported algorithms? (RS256, ES256, …)
- Storage: `~/hdb/keys/` alongside TLS certs?
- Ops API: new `upload_jwt_key` operation, or extend `add_certificate`?
- Grace period for old tokens — operator-configurable?

---

🤖 Filed by Claude on behalf of Kris.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.