# Payaramicro with MicroShed JWT issue

**URL:** <https://forum.payara.fish/t/payaramicro-with-microshed-jwt-issue/130>\
**Category:** Technical Discussion\
**Created:** [November 12, 2021, 3:24pm UTC](https://forum.payara.fish/t/payaramicro-with-microshed-jwt-issue/130 "2021-11-12T15:24:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Osama](https://avatars.discourse-cdn.com/v4/letter/o/f05b48/32.png) [@Osama](https://forum.payara.fish/u/Osama)\
**Post date:** [November 12, 2021, 3:24pm UTC](https://forum.payara.fish/t/payaramicro-with-microshed-jwt-issue/130/1 "2021-11-12T15:24:51Z")

</div>

Hi,  
I’ve a project generated PayaraMicro MP 3.0, application, it has Mp JWT (private key generated in file).  
I created a secured API [@RolesAllowed Method]  
when I test with Microshed, I noticed that when using @ RESTClient when I specify @ JwtConfig,  
it fails to invoke my secured API, with 401 unauthorized error.  
I noticed that @ JwtConfig uses jose4j library, which generates the Keys internally,  
I need some way to provide the same keys I am using on my payaramicro project.

@rudy.de.busscher  
thanks in advance

---

<div class="post-metadata">

**Author:** ![rudy.de.busscher](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.payara.fish/rudy.de.busscher/32/26_2.png) [@rudy.de.busscher](https://forum.payara.fish/u/rudy.de.busscher)\
**Post date:** [November 19, 2021, 8:20am UTC](https://forum.payara.fish/t/payaramicro-with-microshed-jwt-issue/130/2 "2021-11-19T08:20:20Z")

</div>

Hi,

I’m trying to figure out what’s causing the keys to not pick up correctly.

Rudy

---

<div class="post-metadata">

**Author:** ![rudy.de.busscher](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.payara.fish/rudy.de.busscher/32/26_2.png) [@rudy.de.busscher](https://forum.payara.fish/u/rudy.de.busscher)\
**Post date:** [November 20, 2021, 5:48pm UTC](https://forum.payara.fish/t/payaramicro-with-microshed-jwt-issue/130/3 "2021-11-20T17:48:35Z")

</div>

Hi,

The keys are picked up correctly but the JWT token created by the MicroShed Testing framework is leaving out a few claims that we require (as they are recommended by the JWT specification).

You can have a look at the example in this [Github Repository](https://github.com/rdebusscher/payara-microshed-examples).

Important to know, also at the readme of the repository;

- Disable the check on the type header
- Add the jti claim in the @JWTConfig.

You cannot provide the keys for the test project your self (Payara Micro needs to public key, not the private key for normal operations)

Regards  
Rudy
