Introducing HTTP > Make a JWT request module

Overview
We’ve added a new HTTP module: HTTP > Make a JWT request. This module mirrors the behavior of the existing HTTP > Make a request module but builds, signs, and injects a short‑lived JSON Web Token (JWT) based on the claims you provide. By default the signed JWT is sent as an Authorization: Bearer <jwt> header so you can call APIs that require signed JWT authentication without a separate token‑generation step in your scenario.
What’s new
- Make a JWT request module — a new HTTP module that creates, signs, and attaches a JWT to the outgoing request.
- Claims input — provide standard and custom claims (iss, sub, aud, exp, nbf, jti, and custom claims) in the module UI.
- Automatic signing — the module signs the JWT with the key material you supply and inserts it into the request (default: Authorization Bearer).
- Request parity — supports the same HTTP method, headers, body, query, timeout, and retry controls you already use in the HTTP Make a request module.
How it works
- Open your scenario and add HTTP > Make a JWT request where you need a signed JWT.
- Enter the request details as you would in the normal HTTP module (method, URL, headers, body, timeout, retries).
- In the JWT section, provide claims (for example
iss,sub,aud, andexp) and any custom claims required by the API. - Upload or paste the signing key/secret and select the signing algorithm your target service expects.
- The module generates and signs the JWT at execution time and injects it into the request (by default as
Authorization: Bearer <jwt>). - The HTTP call is executed with the signed token included; response handling and retries follow your configured module settings.
Why this matters
- Simpler scenarios — remove the extra steps and modules previously required to create and store short‑lived JWTs.
- Faster integration — authenticate to JWT‑based APIs directly within the HTTP module, reducing scenario complexity.
- Reduced secrets surface — signing keys are provided per module and not stored as separate tokens in your scenario flow (subject to your organization’s secret management policies).
How to get started
- Edit your scenario and replace or add HTTP > Make a JWT request where JWT auth is required.
- Fill in the HTTP request fields (method, URL, headers, body, timeout, Retry Count).
- In the JWT settings:
- Enter the claims required by your API (iss, sub, aud, exp, etc.).
- Supply the signing key/secret and choose the signing algorithm.
- Optionally change how the JWT is included (default: Authorization Bearer). If supported, you can place the token in a custom header or in the request body per API requirements.
- Save and test the module by triggering the scenario and verifying the target API accepts the signed JWT.
Troubleshooting (quick)
- Authentication failures: Confirm the claims (iss, aud, sub) and signing algorithm match the API’s expectations and that the signing key is valid.
- Token expiry: Ensure
expis set appropriately and synchronized with the API’s clock skew tolerance. - Unexpected header placement: By default the module uses
Authorization: Bearer. If the API expects the JWT elsewhere, set the module to place the token in the required header or body field. - Retries and timeouts: The module follows configured Timeout and Retry Count values; remember signed tokens are generated per attempt and any long retry/backoff strategy affects total execution time.
Documentation
Feedback and support
Tell us how you’re using the Make a JWT request module or request enhancements (examples: support for key rotation hooks, built‑in JWK retrieval, per‑claim templates, or automatic time skew handling) by:
- Posting in the Experience League Community thread for the HTTP connector/module.
- Opening a support ticket via the Admin Console Support portal if you encounter unexpected behavior.
- Including example requests, the API’s JWT expectations, and scenario metadata when reporting connector issues to help us diagnose problems faster.
We hope this makes it easier to integrate with APIs that require signed JWTs. Try the new HTTP > Make a JWT request module and let us know what additional JWT controls you’d like to see next.
