TokenValidator Class
JWT token validator using PyJWKClient for simplified validation.
Initialize the token validator.
Constructor
TokenValidator(jwt_validation_options: JwtValidationOptions)
Parameters
| Name | Description |
|---|---|
|
jwt_validation_options
Required
|
Configuration for JWT validation |
Methods
| for_entra |
Create a validator for Entra ID tokens. |
| for_service |
Create a validator for Bot Framework service tokens. |
| validate_token |
Validate a JWT token. |
for_entra
Create a validator for Entra ID tokens.
for_entra(app_id: str, tenant_id: str | None, scope: str | None = None, application_id_uri: str | None = None, cloud: CloudEnvironment | None = None) -> TokenValidator
Parameters
| Name | Description |
|---|---|
|
app_id
Required
|
The app's Microsoft App ID (used for audience validation) |
|
tenant_id
Required
|
The Azure AD tenant ID |
|
scope
|
Optional scope that must be present in the token Default value: None
|
|
application_id_uri
|
Optional Application ID URI from Azure portal. Matches webApplicationInfo.resource in the app manifest. Default value: None
|
|
cloud
|
Optional cloud environment for sovereign cloud support Default value: None
|
for_service
Create a validator for Bot Framework service tokens.
for_service(app_id: str, service_url: str | None = None, cloud: CloudEnvironment | None = None) -> TokenValidator
Parameters
| Name | Description |
|---|---|
|
app_id
Required
|
The bot's Microsoft App ID (used for audience validation) |
|
service_url
|
Optional service URL to validate against token claims Default value: None
|
|
cloud
|
Optional cloud environment for sovereign cloud support Default value: None
|
validate_token
Validate a JWT token.
async validate_token(raw_token: str, service_url: str | None = None, scope: str | None = None) -> Dict[str, Any]
Parameters
| Name | Description |
|---|---|
|
raw_token
Required
|
The raw JWT token string |
|
service_url
|
Optional service URL to validate against token claims Default value: None
|
|
scope
|
Optional scope that must be present in the token Default value: None
|
Returns
| Type | Description |
|---|---|
|
The decoded JWT payload if validation is successful |
Exceptions
| Type | Description |
|---|---|
|
jwt.InvalidTokenError
|
When token validation fails |