<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic POST calls failing with 403 when using JWT Authentication in Integration, Extension &amp; APIs</title>
    <link>https://community.qlik.com/t5/Integration-Extension-APIs/POST-calls-failing-with-403-when-using-JWT-Authentication/m-p/2486840#M21373</link>
    <description>&lt;P&gt;Hi Team,&lt;BR /&gt;We are facing issues with JWT Authentication, it works all good for GET calls&lt;BR /&gt;But for POST it fails with 403, the account that we are using to create the JWT has all permissions (API key created using same account works all good with GET, POST calls)&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;payload = {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"iat"&lt;/SPAN&gt;&lt;SPAN&gt;: datetime.utcnow(),&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"exp"&lt;/SPAN&gt;&lt;SPAN&gt;: datetime.utcnow() &lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN&gt; timedelta(seconds=&lt;/SPAN&gt;&lt;SPAN&gt;600&lt;/SPAN&gt;&lt;SPAN&gt;),&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"nbf"&lt;/SPAN&gt;&lt;SPAN&gt;: datetime.utcnow() &lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; timedelta(seconds=&lt;/SPAN&gt;&lt;SPAN&gt;400&lt;/SPAN&gt;&lt;SPAN&gt;),&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"iss"&lt;/SPAN&gt;&lt;SPAN&gt;: issuer,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"sub"&lt;/SPAN&gt;&lt;SPAN&gt;: issuer,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"subType"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"user"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"name"&lt;/SPAN&gt;&lt;SPAN&gt;: user_name,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"email"&lt;/SPAN&gt;&lt;SPAN&gt;: user_email,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"email_verified"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;True&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"aud"&lt;/SPAN&gt;&lt;SPAN&gt;: JWT_AUDIENCE,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"jti"&lt;/SPAN&gt;&lt;SPAN&gt;: secrets.token_hex(&lt;/SPAN&gt;&lt;SPAN&gt;64&lt;/SPAN&gt;&lt;SPAN&gt;),&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"groups"&lt;/SPAN&gt;&lt;SPAN&gt;: [&lt;/SPAN&gt;&lt;SPAN&gt;"Administrators"&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;"Sales"&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;"Marketing"&lt;/SPAN&gt;&lt;SPAN&gt;],&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; }&lt;BR /&gt;&lt;/SPAN&gt;Is there another permission required for POST calls in JWT as we could not find anything in documentation&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 14 Oct 2024 10:38:42 GMT</pubDate>
    <dc:creator>divya_vishwakarma</dc:creator>
    <dc:date>2024-10-14T10:38:42Z</dc:date>
    <item>
      <title>POST calls failing with 403 when using JWT Authentication</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/POST-calls-failing-with-403-when-using-JWT-Authentication/m-p/2486840#M21373</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;We are facing issues with JWT Authentication, it works all good for GET calls&lt;BR /&gt;But for POST it fails with 403, the account that we are using to create the JWT has all permissions (API key created using same account works all good with GET, POST calls)&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;payload = {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"iat"&lt;/SPAN&gt;&lt;SPAN&gt;: datetime.utcnow(),&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"exp"&lt;/SPAN&gt;&lt;SPAN&gt;: datetime.utcnow() &lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN&gt; timedelta(seconds=&lt;/SPAN&gt;&lt;SPAN&gt;600&lt;/SPAN&gt;&lt;SPAN&gt;),&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"nbf"&lt;/SPAN&gt;&lt;SPAN&gt;: datetime.utcnow() &lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; timedelta(seconds=&lt;/SPAN&gt;&lt;SPAN&gt;400&lt;/SPAN&gt;&lt;SPAN&gt;),&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"iss"&lt;/SPAN&gt;&lt;SPAN&gt;: issuer,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"sub"&lt;/SPAN&gt;&lt;SPAN&gt;: issuer,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"subType"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"user"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"name"&lt;/SPAN&gt;&lt;SPAN&gt;: user_name,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"email"&lt;/SPAN&gt;&lt;SPAN&gt;: user_email,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"email_verified"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;True&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"aud"&lt;/SPAN&gt;&lt;SPAN&gt;: JWT_AUDIENCE,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"jti"&lt;/SPAN&gt;&lt;SPAN&gt;: secrets.token_hex(&lt;/SPAN&gt;&lt;SPAN&gt;64&lt;/SPAN&gt;&lt;SPAN&gt;),&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;"groups"&lt;/SPAN&gt;&lt;SPAN&gt;: [&lt;/SPAN&gt;&lt;SPAN&gt;"Administrators"&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;"Sales"&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;"Marketing"&lt;/SPAN&gt;&lt;SPAN&gt;],&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; }&lt;BR /&gt;&lt;/SPAN&gt;Is there another permission required for POST calls in JWT as we could not find anything in documentation&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 14 Oct 2024 10:38:42 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/POST-calls-failing-with-403-when-using-JWT-Authentication/m-p/2486840#M21373</guid>
      <dc:creator>divya_vishwakarma</dc:creator>
      <dc:date>2024-10-14T10:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: POST calls failing with 403 when using JWT Authentication</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/POST-calls-failing-with-403-when-using-JWT-Authentication/m-p/2488427#M21410</link>
      <description>&lt;P&gt;Any help that i can get here?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 13:19:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/POST-calls-failing-with-403-when-using-JWT-Authentication/m-p/2488427#M21410</guid>
      <dc:creator>divya_vishwakarma</dc:creator>
      <dc:date>2024-10-22T13:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: POST calls failing with 403 when using JWT Authentication</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/POST-calls-failing-with-403-when-using-JWT-Authentication/m-p/2508060#M21881</link>
      <description>&lt;P&gt;Having the same issue...&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:34:34 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/POST-calls-failing-with-403-when-using-JWT-Authentication/m-p/2508060#M21881</guid>
      <dc:creator>Haclark</dc:creator>
      <dc:date>2025-03-03T15:34:34Z</dc:date>
    </item>
  </channel>
</rss>

