# IdentityJwtAuth

> Resource IdentityJwtAuth in pulumi-infisical.

<!-- Generated from the pulumi-infisical SDK. -->

Resource IdentityJwtAuth in pulumi-infisical.

Pulumi type: `infisical:index/identityJwtAuth:IdentityJwtAuth`.

`name` is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

## Example

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

```ts
import * as infisical from "pulumi-infisical"

const resource = new infisical.IdentityJwtAuth("identityJwtAuth", {
  configurationType: "<configurationType>",
  identityId: "<identityId>",
})
```

## Arguments

| Property                  | Type                                            | Required | Description                                                                                                                       |
| ------------------------- | ----------------------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `accessTokenMaxTtl`       | `number`                                        | no       | The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000              |
| `accessTokenNumUsesLimit` | `number`                                        | no       | The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default: 0            |
| `accessTokenTrustedIps`   | `IdentityJwtAuthAccessTokenTrustedIp (input)[]` | no       | A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address. |
| `accessTokenTtl`          | `number`                                        | no       | The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000                      |
| `boundAudiences`          | `string[]`                                      | no       | The list of intended recipients.                                                                                                  |
| `boundClaims`             | `{ [key: string]: string }`                     | no       | The attributes that should be present in the JWT for it to be valid.                                                              |
| `boundIssuer`             | `string`                                        | no       | The unique identifier of the identity provider issuing the JWTs.                                                                  |
| `boundSubject`            | `string`                                        | no       | The expected principal that is the subject of the JWT.                                                                            |
| `configurationType`       | `string`                                        | yes      | The configuration type of the JWT auth. Must be 'jwks' or 'static'.                                                               |
| `identityId`              | `string`                                        | yes      | The ID of the identity to attach the configuration onto.                                                                          |
| `jwksCaCert`              | `string`                                        | no       | The PEM-encoded CA certificate for validating the TLS connection to the JWKS URL.                                                 |
| `jwksUrl`                 | `string`                                        | no       | The URL used to retrieve the JSON Web Key Set (JWKS) for verifying JWTs. Required when `configurationType` is 'jwks'.             |
| `publicKeys`              | `string[]`                                      | no       | A list of PEM-encoded public keys used to verify JWTs. Required when `configurationType` is 'static'.                             |

## Outputs

Computed outputs are produced by the provider. They are not constructor arguments.

| Property                  | Type                                             | Computed | Description                                                                                                                       |
| ------------------------- | ------------------------------------------------ | -------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `accessTokenMaxTtl`       | `number`                                         | no       | The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000              |
| `accessTokenNumUsesLimit` | `number`                                         | no       | The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default: 0            |
| `accessTokenTrustedIps`   | `IdentityJwtAuthAccessTokenTrustedIp (output)[]` | no       | A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address. |
| `accessTokenTtl`          | `number`                                         | no       | The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000                      |
| `boundAudiences`          | `string[]`                                       | no       | The list of intended recipients.                                                                                                  |
| `boundClaims`             | `{ [key: string]: string }`                      | no       | The attributes that should be present in the JWT for it to be valid.                                                              |
| `boundIssuer`             | `string`                                         | no       | The unique identifier of the identity provider issuing the JWTs.                                                                  |
| `boundSubject`            | `string`                                         | no       | The expected principal that is the subject of the JWT.                                                                            |
| `configurationType`       | `string`                                         | no       | The configuration type of the JWT auth. Must be 'jwks' or 'static'.                                                               |
| `identityId`              | `string`                                         | no       | The ID of the identity to attach the configuration onto.                                                                          |
| `jwksCaCert`              | `string`                                         | no       | The PEM-encoded CA certificate for validating the TLS connection to the JWKS URL.                                                 |
| `jwksUrl`                 | `string`                                         | no       | The URL used to retrieve the JSON Web Key Set (JWKS) for verifying JWTs. Required when `configurationType` is 'jwks'.             |
| `publicKeys`              | `string[]`                                       | no       | A list of PEM-encoded public keys used to verify JWTs. Required when `configurationType` is 'static'.                             |

## `IdentityJwtAuthAccessTokenTrustedIp (input)`

Input object `IdentityJwtAuthAccessTokenTrustedIp`. Fields below belong to this object, not to the parent.

| Property    | Type     | Required | Description |
| ----------- | -------- | -------- | ----------- |
| `ipAddress` | `string` | no       |             |

## `IdentityJwtAuthAccessTokenTrustedIp (output)`

Output object `IdentityJwtAuthAccessTokenTrustedIp`. Fields below belong to this object.

| Property    | Type     | Always present | Description |
| ----------- | -------- | -------------- | ----------- |
| `ipAddress` | `string` | yes            |             |
