[Automated] Draft docs (agentgateway): fix(jwt): select providers by issuer and kid - #1128
Merged
Merged
Conversation
…issuer and kid Signed-off-by: GitHub Action <action@github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Art Berger <art.berger@solo.io>
artberger
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
agentgateway/agentgateway#3611 — fix(jwt): select providers by issuer and kid
Docs versions:
standalone/main,kubernetes/mainWhat changes for users: JWT authentication now selects a provider by both the token's
issclaim andkidheader before validation. Multi-tenant deployments can use issuers that publish the samekidvalue without the gateway validating a token against the wrong issuer.What the docs now say: The JWT overview, Kubernetes JWT setup guide, and standalone JWT authentication page now explain that provider selection uses
issandkid, and why that matters when multiple JWT providers are configured.Not verified: No cluster commands were run in this sandbox; the configuration is unrun.
How
agentgateway-3611was drafted, and what was not verifiedPlan, and what changed it
jwt-setup.mdalready has a Multiple JWT providers section, andjwt-authn.mdcarries the matching standalone claim semantics.Why a documentation change is necessary
The diff changes JWT validation so provider selection uses the unverified
issclaim together with thekidheader before signature and claim validation. The target pages already explainissuer,jwks, and multiple JWT providers, but they did not state that akidis only unique within one issuer's JWKS. A reader configuring multiple identity providers with collidingkidvalues would not know that the new behavior selects the provider by issuer first.What changed on disk
assets/agw-docs/pages/security/jwt-about.md— Adds a gated overview note for main about provider selection byissandkid.assets/agw-docs/pages/security/jwt-setup.md— Adds the same gated behavior note beside the Multiple JWT providers example.content/docs/standalone/main/documentation/configuration/security/jwt-authn.md— Adds the standalone main-tree note about provider selection byissandkid.How to verify this change
issuervalues whose JWKS documents publish the samekid, then protect a route with the JWT policy.200.issmatches one provider but whoseaudis wrong:401, and the proxy log reportsInvalidAudiencefor the matching issuer rather than validating against a provider that only shares thekid.Proposed release note
The item is labelled
fix, so placement may need reviewer handling if the release-note script does not map plain fixes to a section.What was not verified
The configuration was not applied to a cluster, and no standalone runtime command was run. The
cluster-facts.mdfile was used only as the Kubernetes API surface for field names and types; it is not a test result.How the pages were chosen (triage report)
Draft a documentation change
agentgateway/agentgateway#3611 — fix(jwt): select providers by issuer and kid
agentgateway/websiteWarnings
Draft branch:
pr-tracker-draft-agentgateway-3611