29
Authentication in microservices
(feddit.dk)
Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!
Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.
Hope you enjoy the instance!
Rules
Follow the wormhole through a path of communities !webdev@programming.dev
When I've done this it's generally done with JWTs where each micro service is configured with a trusted public key that is used to authenticate the JWT. The JWT can be sent to the client when they log in, and used to authenticate all API requests (forwarding the JWT as necessary for service-to-service requests). It's also possible to have a gateway mint JWTs after using some other means to authenticate client requests.
Sometimes service-to-service requests don't have a client request in context to pull a JWT from. In those cases you need another authentication mechanism, like a different signed token, or a shared secret.