When attempting to validate the issued JWT Token by a backend system, an error regarding an 'invalid issuer' is being thrown. How can this issue be resolved?
Cause
The issuer value was missing a trailing slash '/' and protocol on the issuer URL when configuring the backend middleware.
Solution
Make sure the keys used in the backend to validate the JWT are an exact match of the ones from the well-known endpoint for the appropriate Auth0 tenant. If any of those values fail, there is typically a descriptive error along with the 401 status code such as "invalid issuer" to help with debugging efforts.
Recommended content
No recommended content found...
Was this content helpful?
Yes - the content was helpful
No - the content was not helpful
Loading
JWT Verification from a Backend API | Auth0 Support