The microprofile-jwt
quickstart demonstrates the use of the MicroProfile JWT specification in WildFly.
The microprofile-jwt
quickstart demonstrates the use of the MicroProfile JWT
specification in WildFly. Within the quickstart the following topics will be covered: -
Creation of a simple Rest deployment as the base of the quickstart.
Initial calls to verify the endpoint is accessible.
Creation of public and private keys to enable generation and validation of JWT tokens.
Creation of a simple utility to generate JWT tokens.
Activation of
authentication for the deployment. -
Calling the rest endpoint with the generated JWT token.
Enabling authorization based on claims contained within the JWT token.
Injection of claims from the JWT token.
To make it possible to execute this quickstart out of the box the public and private key are included in the quickstart, as both keys are published publicly they should never be used in a production environment.
Although this quickstart demonstrates the functionality using a token generation utility, within a production environment it would be more appropriate to make use of an identity provider to issue the tokens.
The application this project produces is designed to be run on WildFly Application Server 32 or later.
All you need to build this project is Java 11.0 (Java SDK 11) or later and Maven 3.6.0 or later. See Configure Maven to Build and Deploy the Quickstarts to make sure you are configured correctly for testing the quickstarts.
Open a terminal and navigate to the root of the WildFly directory.
Start the WildFly server with the MicroProfile profile by typing the following command.
$ WILDFLY_HOME/bin/ -c standalone-microprofile.xml
NoteFor Windows, use the WILDFLY_HOME\bin\standalone.bat
One of the benefits of using MicroProfile JWT is that the configuration is contained entirely within the deployment, for this reason no manual configuration of the server is required to execute the quickstart.
We recommend that you follow the instructions in the next sections and create the application step by step as this will provide a better foundation for creating your own MP-JWT secured deployment, however if you want to jump straight to executing the quickstarts the steps here can be followed to execute the included code.
The quickstart can be deployed to the running application server using the following command: -
mvn package wildfly:deploy
An unauthenticated call can be made to one of the deployed endpoints using the following command: -
$ curl http://localhost:8080/microprofile-jwt/Sample/helloworld
Hello anonymous
Using the token generation utility contained within the quickstart a new JWT can be created using the following command: -
$ mvn exec:java -Dexec.mainClass=org.wildfly.quickstarts.mpjwt.TokenUtil -Dexec.classpathScope=test -Dexec.args="testUser 2017-09-15 Echoer Subscriber"
JWT Header - {"kid":"Test Key","typ":"jwt","alg":"RS256"}
JWT Claims - {"sub":"testUser","upn":"testUser","iss":"quickstart-jwt-issuer","aud":"jwt-audience","groups":["Echoer","Subscriber"],"birthdate":"2017-09-15","jti":"3b89e56f-b8fd-4d5f-a1ed-080b958873f9","iat":1579886816,"exp":1579901216}
Generated JWT Token
A call can now be made to the first endpoint using the generated JWT token within the request message: -
$ curl -H "Authorization: Bearer eyJ...XPA" http://localhost:8080/microprofile-jwt/Sample/helloworld
Hello testUser
The quickstart also contains an endpoint which requires the identity to be granted the Subscriber
role, using a generated token this can be
called using the following command: -
$ curl -H "Authorization: Bearer ey..XPA" http://localhost:8080/microprofile-jwt/Sample/subscription
hello + testUser, hasJWT: true
If a token is now generated and use without the Subscriber
group access to this endpoint should be rejected.
$ mvn exec:java -Dexec.mainClass=org.wildfly.quickstarts.mpjwt.TokenUtil -Dexec.classpathScope=test -Dexec.args="testUser 2017-09-15 Echoer"
JWT Header - {"kid":"Test Key","typ":"jwt","alg":"RS256"}
JWT Claims - {"sub":"testUser","upn":"testUser","iss":"quickstart-jwt-issuer","aud":"jwt-audience","groups":["Echoer"],"birthdate":"2017-09-15","jti":"4346874f-eb48-4d84-ab51-c6efd1cd22d5","iat":1580136970,"exp":1580151370}
Generated JWT Token
$ curl -H "Authorization: Bearer ey..APw" http://localhost:8080/microprofile-jwt/Sample/subscription
Access forbidden: role not allowed
The quickstart also contains an endpoint that makes use of the birthdate
claim to calculate how long until the callers birthday, this can be called using a token which contains the Subscriber
$ curl -H "Authorization: Bearer ey..XPA" http://localhost:8080/microprofile-jwt/Sample/birthday
7 months and 19 days until your next birthday.
This section has been a fast run through of the commands required to deploy the quickstart, generate JWT tokens and call the various endpoints, for further information as to how this was achieved please read through the next section where the process to generate this quickstart from scratch is described step by step.
It is also possible to run each of these calls from the test case included in the quickstart.
This quickstart includes integration tests, which are located under the src/test/
directory. The integration tests verify that the quickstart runs correctly when deployed on the server.
Follow these steps to run the integration tests.
Make sure WildFly server is started.
Make sure the quickstart is deployed.
Type the following command to run the
goal with theintegration-testing
profile activated.$ mvn verify -Pintegration-testing
In this section we will go through the steps to create a new JAX-RS deployment from scratch and incrementally add support for MicroProfile JWT including token generation, activation of authorization and the injection of claims.
This quickstart will be making use of JAX-RS endpoints secured using MicroProfile JWT so the first step
is to generate a new webapp
project: -
mvn archetype:generate -DinteractiveMode=false \
-DarchetypeGroupId=org.apache.maven.archetypes \
-DarchetypeArtifactId=maven-archetype-webapp \
-DgroupId=org.wildfly.quickstarts -DartifactId=microprofile-jwt \
cd microprofile-jwt
The changes required on the project can be performed using a text editor, however you may prefer to import the project into your favourite IDE.
Next the project’s pom.xml
should be updated so the dependencies required by this quickstart are
available and so we have a plug-in installed which can deploy the quickstart directly to WildFly.
Add the following properties to the pom.xml
Also the project can be updated to use Java 11 as the minimum.
Before the dependencies are defined add the following boms.
By using boms the majority of dependencies used within this quickstart align with the version uses by the application server.
The following dependencies can now be added to the project.
Also add the following test scoped dependencies.
Within the <build></build>
section of the project add the following plug-in definition.
Once the project has been developed this plug-in will handle the deployment to the application server.
Setup the required Maven repositories (if you don’t have them set up in Maven global settings):
<name>JBoss Public Maven Repository</name>
<name>Red Hat GA Maven Repository</name>
<name>JBoss Public Maven Repository</name>
<name>Red Hat GA Maven Repository</name>
The generated project is a standard web application so the next step will be to delete the files not
required by this quickstart and add the JAX-RS application and a helloWorld
Under src/main/webapp
delete the generated index.jsp
Within the directory src/main/webapp/WEB-INF
add an empty beans.xml
file, this will act as a trigger
to enable CDI for the deployment.
Under src/main
create a new java
directory to hold the Java class to be added to the project.
Add the following class in the org.wildfly.quickstarts.mpjwt
package, this will be the main trigger to
process the deployment as a JAX-RS deployment.
package org.wildfly.quickstarts.mpjwt;
import org.eclipse.microprofile.auth.LoginConfig;
@LoginConfig(authMethod="MP-JWT", realmName="MP JWT Realm")
public class App extends Application {}
Also within the org.wildfly.quickstarts.mpjwt
package add the following endpoint.
package org.wildfly.quickstarts.mpjwt;
public class SampleEndPoint {
public String helloworld() {
return "Hello World";
At this stage the project contains a simple JAX-RS endpoint we can deploy to the server and invoke to verify everything is working as expected before moving on to enable JWT based authentication and authorization.
First build the example and deploy it to the previously started application server.
Compile the application code and deploy it to WildFly
$ mvn clean package wildfly:deploy
In the output of the application server’s console check the deployment deployed successfully.
15:48:22,159 INFO [org.jboss.resteasy.resteasy_jaxrs.i18n] (ServerService Thread Pool -- 78) RESTEASY002225: Deploying class org.wildfly.quickstarts.mpjwt.App$Proxy$_$$_WeldClientProxy
15:48:22,193 INFO [org.wildfly.extension.undertow] (ServerService Thread Pool -- 78) WFLYUT0021: Registered web context: '/microprofile-jwt' for server 'default-server'
15:48:22,239 INFO [] (management-handler-thread - 1) WFLYSRV0010: Deployed "microprofile-jwt.war" (runtime-name : "microprofile-jwt.war")
The endpoint can now be called using the following command: -
$ curl http://localhost:8080/microprofile-jwt/Sample/helloworld
Hello World
Alternative HTTP clients can be used however later on we will be adding custom headers to the HTTP request which can be acomplished directly with the curl
The first update to make to the project is to modify the /helloworld
to report the name of the presently authenticated identity.
Make the following changes to the previously created org.wildfly.quickstarts.mpjwt.SampleEndPoint
Add the following import
statements to the class.
Then replace the existing helloWorld()
method with the following: -
public String helloworld(@Context SecurityContext securityContext) {
Principal principal = securityContext.getUserPrincipal();
String caller = principal == null ? "anonymous" : principal.getName();
return "Hello " + caller;
As before, deploy and call the endpoint.
$ mvn package wildfly:deploy
$ curl http://localhost:8080/microprofile-jwt/Sample/helloworld
Hello anonymous
Now that we have a deployable project our next step on the project will be to enable MP-JWT
authentication, however before we can do this a couple of steps are
required the first being the generation of a public / private key pair for token signing and verification.
For MicroProfile JWT we only require the keys, we do not require an X509Certificate so we can use openssl to generate the raw keys.
$ openssl genpkey -algorithm RSA -out private.pem -pkeyopt rsa_keygen_bits:2048
From this we can then export the public key that will be included in the deployment.
$ mkdir -p src/main/resources/META-INF
$ openssl rsa -in private.pem -pubout -out src/main/resources/META-INF/public.pem
The commands used here offer no protection of the generated keys, in a real world environment any private keys that can be used for token generation should be handled securely.
The next step is to add a utility to the project which can be used to generate JWT tokens for use with this example.
First create a directory to hold the test code.
$ mkdir -p src/test/java
Under src/test/java
add the following utility class to the org.wildfly.quickstarts.mpjwt
package org.wildfly.quickstarts.mpjwt;
import java.nio.charset.StandardCharsets;
import java.util.Base64;
import java.util.UUID;
import jakarta.json.Json;
import jakarta.json.JsonArrayBuilder;
import jakarta.json.JsonObjectBuilder;
import com.nimbusds.jose.JOSEObjectType;
import com.nimbusds.jose.JWSAlgorithm;
import com.nimbusds.jose.JWSHeader;
import com.nimbusds.jose.JWSObject;
import com.nimbusds.jose.JWSSigner;
import com.nimbusds.jose.Payload;
import com.nimbusds.jose.crypto.RSASSASigner;
public class TokenUtil {
private static PrivateKey loadPrivateKey(final String fileName) throws Exception {
try (InputStream is = new FileInputStream(fileName)) {
byte[] contents = new byte[4096];
int length =;
String rawKey = new String(contents, 0, length, StandardCharsets.UTF_8)
.replaceAll("-----BEGIN (.*)-----", "")
.replaceAll("-----END (.*)----", "")
.replaceAll("\r\n", "").replaceAll("\n", "").trim();
PKCS8EncodedKeySpec keySpec = new PKCS8EncodedKeySpec(Base64.getDecoder().decode(rawKey));
KeyFactory keyFactory = KeyFactory.getInstance("RSA");
return keyFactory.generatePrivate(keySpec);
public static String generateJWT(final String principal, final String birthdate, final String...groups) throws Exception {
PrivateKey privateKey = loadPrivateKey("private.pem");
JWSSigner signer = new RSASSASigner(privateKey);
JsonArrayBuilder groupsBuilder = Json.createArrayBuilder();
for (String group : groups) { groupsBuilder.add(group); }
long currentTime = System.currentTimeMillis() / 1000;
JsonObjectBuilder claimsBuilder = Json.createObjectBuilder()
.add("sub", principal)
.add("upn", principal)
.add("iss", "quickstart-jwt-issuer")
.add("aud", "jwt-audience")
.add("birthdate", birthdate)
.add("jti", UUID.randomUUID().toString())
.add("iat", currentTime)
.add("exp", currentTime + 14400);
JWSObject jwsObject = new JWSObject(new JWSHeader.Builder(JWSAlgorithm.RS256)
.type(new JOSEObjectType("jwt"))
.keyID("Test Key").build(),
new Payload(;
return jwsObject.serialize();
public static void main(String[] args) throws Exception {
if (args.length < 2) throw new IllegalArgumentException("Usage TokenUtil {principal} {birthdate} {groups}");
String principal = args[0];
String birthdate = args[1];
String[] groups = new String[args.length - 2];
System.arraycopy(args, 2, groups, 0, groups.length);
String token = generateJWT(principal, birthdate, groups);
String[] parts = token.split("\\.");
System.out.println(String.format("\nJWT Header - %s", new String(Base64.getDecoder().decode(parts[0]), StandardCharsets.UTF_8)));
System.out.println(String.format("\nJWT Claims - %s", new String(Base64.getDecoder().decode(parts[1]), StandardCharsets.UTF_8)));
System.out.println(String.format("\nGenerated JWT Token \n%s\n", token));
After adding the class the project will need to be compiled again and can then be executed using Maven.
$ mvn package
$ mvn exec:java -Dexec.mainClass=org.wildfly.quickstarts.mpjwt.TokenUtil -Dexec.classpathScope=test -Dexec.args="testUser 2017-09-15 Echoer Subscriber"
JWT Header - {"kid":"Test Key","typ":"jwt","alg":"RS256"}
JWT Claims - {"sub":"testUser","upn":"testUser","iss":"quickstart-jwt-issuer","aud":"jwt-audience","groups":["Echoer","Subscriber"],"birthdate":"2017-09-15","jti":"3b89e56f-b8fd-4d5f-a1ed-080b958873f9","iat":1579886816,"exp":1579901216}
Generated JWT Token
We now have everything we need to activate MP-JWT
authentication on the deployment and start accepting JWT tokens within the HTTP requests.
At this stage we have a basic JAX-RS deployment, a pair of keys for the generation of and validation of JWT tokens and a utility to generate JWT tokens. Our next step is to activate MicroProfile JWT authentication for the deployment and we can then make use of some of the advanced features such as role based access control using the groups from within the token and access to individual claims within the token.
The configuration for JWT validation can be contained within a MicroProfile Config properties file, under src/main/resources/META-INF
add a
with the following content.
As before, deploy and call the endpoint.
$ mvn package wildfly:deploy
$ curl http://localhost:8080/microprofile-jwt/Sample/helloworld
Hello anonymous
A new token can now be generated using the TokenUtility created previously and the token passed in as we call the endpoint.
$ curl -H "Authorization: Bearer eyJ...59g" http://localhost:8080/microprofile-jwt/Sample/helloworld
Hello testUser
At this point our first endpoint now supports optional authentication making use of a JWT token.
Now that authentication has been activated we can add another endpoint that requires the caller to have been granted the ‘Subscribers’ role which will be based on the groups in the incoming JWT token.
The following imports should be added to the “SampleEndPoint” class: -
import jakarta.inject.Inject;
import org.eclipse.microprofile.jwt.JsonWebToken;
And then the following new endpoint can be added: -
JsonWebToken jwt;
public String helloRolesAllowed(@Context SecurityContext ctx) {
Principal caller = ctx.getUserPrincipal();
String name = caller == null ? "anonymous" : caller.getName();
boolean hasJWT = jwt.getClaimNames() != null;
String helloReply = String.format("hello + %s, hasJWT: %s", name, hasJWT);
return helloReply;
Within WildFly the JAX-RS deployment is handled by RESTEasy so under src/main/webapp/WEB-INF
add the following to the web.xml to enable RESTEasy authorization checks.
As before, build and deploy the example.
$ mvn package wildfly:deploy
Using a recently generated token the new endpoint can be called.
$ curl -H "Authorization: Bearer ey..59g" http://localhost:8080/microprofile-jwt/Sample/subscription
hello + testUser, hasJWT: true
If a token is now generated without including the “Subscriber” group access should be denied to the endpoint.
$ curl -H "Authorization: Bearer ey..Pw" http://localhost:8080/microprofile-jwt/Sample/subscription
Access forbidden: role not allowed
A final feature that will be explored within this Quickstart is accessing the claims contained within the JWT.
The JWTToken in the previous example can be used to inspect the claims, however it is also possible to inject the specific claim.
The following imports should be added to the “SampleEndPoint” class: -
import java.time.LocalDate;
import java.time.Period;
import java.util.Optional;
import org.eclipse.microprofile.jwt.Claims;
import org.eclipse.microprofile.jwt.Claim;
And then the following new endpoint can be added: -
@Claim(standard = Claims.birthdate)
Optional<String> birthdate;
@RolesAllowed({ "Subscriber" })
public String birthday() {
if (birthdate.isPresent()) {
LocalDate birthdate = LocalDate.parse(this.birthdate.get().toString());
LocalDate today =;
LocalDate next = birthdate.withYear(today.getYear());
if (today.equals(next)) {
return "Happy Birthday";
if (next.isBefore(today)) {
next = next.withYear(next.getYear() + 1);
Period wait = today.until(next);
return String.format("%d months and %d days until your next birthday.", wait.getMonths(), wait.getDays());
return "Sorry, we don't know your birthdate.";
As with the previous endpoint the caller is required to have been granted the Subscriber
role, if a birthdate
claim is present within
the JWT token this endpoint will calculate how many days until the next birthday and wish you happy birthday it if is today.
As before, build and deploy the example.
$ mvn package wildfly:deploy
Using a recently generated token the new endpoint can be called.
$ curl -H "Authorization: Bearer ey..59g" http://localhost:8080/microprofile-jwt/Sample/birthday
7 months and 19 days until your next birthday.
You can use the WildFly JAR Maven plug-in to build a WildFly bootable JAR to run this quickstart.
The quickstart pom.xml
file contains a Maven profile named bootable-jar which configures the bootable JAR building:
Rename the output war to ROOT.war before adding it to the server, so that the
application is deployed in the root web context.
The plugin uses WildFly Glow to discover the feature packs and layers required to run the application, and provisions a server containing those layers.
If you get an error or the server is missing some functionality which cannot be auto-discovered, you can download the WildFly Glow CLI and run the following command to see more information about what add-ons are available:
wildfly-glow show-add-ons
Build the quickstart bootable JAR with the following command:
$ mvn clean package -Pbootable-jar
Run the quickstart application contained in the bootable JAR:
$ java -jar target/microprofile-jwt-bootable.jar
You can now interact with the quickstart application.
After the quickstart application is deployed, the bootable JAR includes the application in the root context. Therefore, any URLs related to the application should not have the |
The integration tests included with this quickstart, which verify that the quickstart runs correctly, may also be run with a bootable jar.
Follow these steps to run the integration tests.
Make sure the bootable jar is provisioned.
$ mvn clean package -Pbootable-jar
Start the WildFly bootable jar, this time using the WildFly Maven Jar Plugin, which is recommend for testing due to simpler automation.
$ mvn wildfly-jar:start -Djar-file-name=target/microprofile-jwt-bootable.jar
Type the following command to run the
goal with theintegration-testing
profile activated, and specifying the quickstart’s URL using
system property, which for a bootable jar by default ishttp://localhost:8080
.$ mvn verify -Pintegration-testing
Shutdown the WildFly bootable jar, this time using the WildFly Maven Jar Plugin too.
$ mvn wildfly-jar:shutdown
On OpenShift, the S2I build with Apache Maven uses an openshift
Maven profile to provision a WildFly server, deploy and run the quickstart in OpenShift environment.
The server provisioning functionality is provided by the WildFly Maven Plugin, and you may find its configuration in the quickstart pom.xml
The parent POM's 'openshift' profile renames the output archive to ROOT.war so that the
application is deployed in the root web context. Add ROOT.war to the server.
You may note that unlike the provisioned-server
profile it uses the cloud context which enables a configuration tuned for OpenShift environment.
The plugin uses WildFly Glow to discover the feature packs and layers required to run the application, and provisions a server containing those layers.
If you get an error or the server is missing some functionality which cannot be auto-discovered, you can download the WildFly Glow CLI and run the following command to see more information about what add-ons are available:
wildfly-glow show-add-ons
This section contains the basic instructions to build and deploy this quickstart to WildFly for OpenShift or WildFly for OpenShift Online using Helm Charts.
You must be logged in OpenShift and have an
client to connect to OpenShift -
Helm must be installed to deploy the backend on OpenShift.
Once you have installed Helm, you need to add the repository that provides Helm Charts for WildFly.
$ helm repo add wildfly
"wildfly" has been added to your repositories
$ helm search repo wildfly
wildfly/wildfly ... ... Build and Deploy WildFly applications on OpenShift
wildfly/wildfly-common ... ... A library chart for WildFly-based applications
Log in to your OpenShift instance using the oc login
The backend will be built and deployed on OpenShift with a Helm Chart for WildFly.
Navigate to the root directory of this quickstart and run the following command:
$ helm install microprofile-jwt -f charts/helm.yaml wildfly/wildfly --wait --timeout=10m0s
NAME: microprofile-jwt
STATUS: deployed
This command will return once the application has successfully deployed. In case of a timeout, you can check the status of the application with the following command in another terminal:
oc get deployment microprofile-jwt
The Helm Chart for this quickstart contains all the information to build an image from the source code using S2I on Java 17:
ref: main
contextDir: microprofile-jwt
replicas: 1
This will create a new deployment on OpenShift and deploy the application.
If you want to see all the configuration elements to customize your deployment you can use the following command:
$ helm show readme wildfly/wildfly
Get the URL of the route to the deployment.
$ oc get route microprofile-jwt -o jsonpath="{}"
Access the application in your web browser using the displayed URL.
The Maven profile named |
The integration tests included with this quickstart, which verify that the quickstart runs correctly, may also be run with the quickstart running on OpenShift.
The integration tests expect a deployed application, so make sure you have deployed the quickstart on OpenShift before you begin. |
Run the integration tests using the following command to run the verify
goal with the integration-testing
profile activated and the proper URL:
$ mvn verify -Pintegration-testing$(oc get route microprofile-jwt --template='{{ }}')
The tests are using SSL to connect to the quickstart running on OpenShift. So you need the certificates to be trusted by the machine the tests are run from. |
As demonstrated within this Quickstart the MicroProfile JWT specification provides an easy way to secure deployments without needing to rely on managed server configuration. The techniques explored in this quickstart can be used to create your own MicroProfile JWT secured enpoints or to add MicroProfile JWT authentication to your existing deployments.