Multiple accounts in a single JWT token

Viewed 40

I am building a solution, where a single user should be able to access resources from a API spaning multiple accounts using a JWT token.

The setup is quite simple: I have a API exposing resources related to an account, e.g:

[api]/account/{account_id}/orders

However a user should be able to access multiple accounts, but with different permissions for each account (like admin and guest). I however am unsure about how this should best be expressed in the access token, and I have not been able to find an example online addressing this issue.

My current idea would be to have a payload like:

{
  "sub": "1234567890",
  "name": "John Doe",
  "iat": 1516239022,
  "aud": "[api]",
  "accounts": [
     {
        "account_id": 123,
        "roles": ["admin"]
     },
     {
        "account_id": 234,
        "roles": ["guest"]
     }
   ]  
}

In theory the "roles" property could be replaced on scopes related to the specific account, mimicking then root level scopes. However, if there exist a standard way to achieve this, I would prefer going in that direction?

0 Answers
Related