1
0
mirror of https://github.com/taigrr/nats.docs synced 2025-01-18 04:03:23 -08:00

Update developing-with-nats/tutorials/jwt.md

Co-authored-by: Colin Sullivan <colin@synadia.com>
This commit is contained in:
Matthias Hanel 2021-02-16 13:09:11 -05:00 committed by GitHub
parent 6397593719
commit 7e80689cd5
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -311,7 +311,7 @@ The referenced NKEY's role determines the JWT content.
3. User JWT: Contain User specific [configuration](https://github.com/nats-io/jwt/blob/e11ce317263cef69619fc1ca743b195d02aa1d8a/user_claims.go#L25) such as Permissions/Limits
In addition, JWT can contain settings related to their decentralized nature, such as expiration/revocation/signing.
At no point do JWT contain the private portion of an NKEY, only signatures that can be verified with public NKEY.
At no point will a JWT contain the private portion of an NKEY. Signatures are verified with public NKEY.
JWT content can be viewed as public, although it's content may reveal which subjects/limits/permissions exist.
#### Key Takeaways