pub struct AccountJwt {
pub issuer: String,
pub subject_account: String,
pub name: String,
pub issued_at: u64,
pub expires: Option<u64>,
pub signing_keys: Vec<String>,
pub claims: AccountClaims,
}Expand description
A NATS account JWT to be signed by its issuing operator key.
Uses the same signing_input / assemble
split as UserJwt: the operator (or operator-signing) key signs the input
in the vault and the seed never materializes.
Fields§
§issuer: StringIssuer = the operator (or operator-signing) public NKey (O…) signing.
subject_account: StringSubject = the account public NKey (A…) the JWT is for.
name: StringHuman-readable account name (the name claim).
issued_at: u64Issued-at time (iat), Unix seconds.
expires: Option<u64>Optional expiry (exp), Unix seconds; None mints a non-expiring token.
signing_keys: Vec<String>Account signing keys (A…) authorized to sign on behalf of the account.
Used only when AccountClaims::signing_keys is empty.
claims: AccountClaimsAdditional account claim fields from nats-io/jwt v2.
Implementations§
Source§impl AccountJwt
impl AccountJwt
Sourcepub fn signing_input(&self) -> Result<String, Error>
pub fn signing_input(&self) -> Result<String, Error>
Produce the JWS signing input (base64url(header).base64url(claims)).
§Errors
Error::Json if claim serialization fails (does not happen for these
types in practice).