{"id":38725273,"url":"https://github.com/statnett/vault-plugin-auth-jwt-auto-roles","last_synced_at":"2026-01-20T18:09:53.073Z","repository":{"id":196228862,"uuid":"694538124","full_name":"statnett/vault-plugin-auth-jwt-auto-roles","owner":"statnett","description":"A Vault plugin to automatically authenticate with all roles matching a JWT (or OIDC) token","archived":false,"fork":false,"pushed_at":"2026-01-13T04:45:03.000Z","size":266,"stargazers_count":0,"open_issues_count":4,"forks_count":3,"subscribers_count":5,"default_branch":"main","last_synced_at":"2026-01-17T20:34:41.446Z","etag":null,"topics":["hashicorp-vault","vault-plugin"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/statnett.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2023-09-21T07:43:13.000Z","updated_at":"2026-01-12T07:07:31.000Z","dependencies_parsed_at":"2023-12-14T16:31:01.087Z","dependency_job_id":"4c0d3d65-ab7f-43a6-a50a-54da769bcad5","html_url":"https://github.com/statnett/vault-plugin-auth-jwt-auto-roles","commit_stats":null,"previous_names":["statnett/vault-plugin-auth-jwt-auto-roles"],"tags_count":28,"template":false,"template_full_name":null,"purl":"pkg:github/statnett/vault-plugin-auth-jwt-auto-roles","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/statnett%2Fvault-plugin-auth-jwt-auto-roles","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/statnett%2Fvault-plugin-auth-jwt-auto-roles/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/statnett%2Fvault-plugin-auth-jwt-auto-roles/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/statnett%2Fvault-plugin-auth-jwt-auto-roles/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/statnett","download_url":"https://codeload.github.com/statnett/vault-plugin-auth-jwt-auto-roles/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/statnett%2Fvault-plugin-auth-jwt-auto-roles/sbom","scorecard":{"id":1237708,"data":{"date":"2025-09-15T13:01:49Z","repo":{"name":"github.com/statnett/vault-plugin-auth-jwt-auto-roles","commit":"ee02d0db945b53fe81c348251a45c2384f4ffb1b"},"scorecard":{"version":"v5.2.1","commit":"ab2f6e92482462fe66246d9e32f642855a691dc1"},"score":7.8,"checks":[{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Warn: jobLevel 'security-events' permission set to 'write': .github/workflows/codeql.yaml:23","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yaml:21","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yaml:22","Warn: jobLevel 'statuses' permission set to 'write': .github/workflows/lint-pr.yml:17","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release-please.yml:16","Warn: jobLevel 'security-events' permission set to 'write': .github/workflows/scorecard.yaml:17","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecard.yaml:19","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecard.yaml:20","Info: topLevel 'contents' permission set to 'read': .github/workflows/ci.yml:8","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yaml:14","Info: topLevel 'contents' permission set to 'read': .github/workflows/go-releaser.yml:9","Info: topLevel 'contents' permission set to 'read': .github/workflows/lint-pr.yml:11","Info: topLevel 'contents' permission set to 'read': .github/workflows/release-please.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/scorecard.yaml:12","Info: topLevel 'contents' permission set to 'read': .github/workflows/snapshot.yml:7"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#token-permissions"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#code-review"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: RenovateBot: .github/renovate.json5:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dependency-update-tool"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":10,"reason":"all dependencies are pinned","details":["Info:  11 out of  11 GitHub-owned GitHubAction dependencies pinned","Info:   4 out of   4 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#pinned-dependencies"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":10,"reason":"15 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#maintained"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#cii-best-practices"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#vulnerabilities"}},{"name":"CI-Tests","score":-1,"reason":"internal error: internal error: Client.Repositories.ListCheckRunsForRef: error during graphqlHandler.setupCheckRuns: non-200 OK status code: 502 Bad Gateway body: \"\u003chtml\u003e\\r\\n\u003chead\u003e\u003ctitle\u003e502 Bad Gateway\u003c/title\u003e\u003c/head\u003e\\r\\n\u003cbody\u003e\\r\\n\u003ccenter\u003e\u003ch1\u003e502 Bad Gateway\u003c/h1\u003e\u003c/center\u003e\\r\\n\u003chr\u003e\u003ccenter\u003enginx\u003c/center\u003e\\r\\n\u003c/body\u003e\\r\\n\u003c/html\u003e\\r\\n\"","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#ci-tests"}},{"name":"SAST","score":-1,"reason":"internal error: internal error: Client.Checks.ListCheckRunsForRef: error during graphqlHandler.setupCheckRuns: non-200 OK status code: 502 Bad Gateway body: \"\u003chtml\u003e\\r\\n\u003chead\u003e\u003ctitle\u003e502 Bad Gateway\u003c/title\u003e\u003c/head\u003e\\r\\n\u003cbody\u003e\\r\\n\u003ccenter\u003e\u003ch1\u003e502 Bad Gateway\u003c/h1\u003e\u003c/center\u003e\\r\\n\u003chr\u003e\u003ccenter\u003enginx\u003c/center\u003e\\r\\n\u003c/body\u003e\\r\\n\u003c/html\u003e\\r\\n\"","details":null,"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#sast"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#fuzzing"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/ci.yml:43"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#packaging"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#security-policy"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.3.7 not signed: https://api.github.com/repos/statnett/vault-plugin-auth-jwt-auto-roles/releases/239000050","Warn: release artifact v0.3.6 not signed: https://api.github.com/repos/statnett/vault-plugin-auth-jwt-auto-roles/releases/223857637","Warn: release artifact v0.3.5 not signed: https://api.github.com/repos/statnett/vault-plugin-auth-jwt-auto-roles/releases/208376874","Warn: release artifact v0.3.4 not signed: https://api.github.com/repos/statnett/vault-plugin-auth-jwt-auto-roles/releases/202016043","Warn: release artifact v0.3.3 not signed: https://api.github.com/repos/statnett/vault-plugin-auth-jwt-auto-roles/releases/194008985","Warn: release artifact v0.3.7 does not have provenance: https://api.github.com/repos/statnett/vault-plugin-auth-jwt-auto-roles/releases/239000050","Warn: release artifact v0.3.6 does not have provenance: https://api.github.com/repos/statnett/vault-plugin-auth-jwt-auto-roles/releases/223857637","Warn: release artifact v0.3.5 does not have provenance: https://api.github.com/repos/statnett/vault-plugin-auth-jwt-auto-roles/releases/208376874","Warn: release artifact v0.3.4 does not have provenance: https://api.github.com/repos/statnett/vault-plugin-auth-jwt-auto-roles/releases/202016043","Warn: release artifact v0.3.3 does not have provenance: https://api.github.com/repos/statnett/vault-plugin-auth-jwt-auto-roles/releases/194008985"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#branch-protection"}},{"name":"Contributors","score":10,"reason":"project has 5 contributing companies or organizations","details":["Info: found contributions from: cert-manager, kubernetes, kubernetes-sigs, statnett, zenior as"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ab2f6e92482462fe66246d9e32f642855a691dc1/docs/checks.md#contributors"}}]},"last_synced_at":"2025-09-15T14:38:40.374Z","repository_id":196228862,"created_at":"2025-09-15T14:38:40.374Z","updated_at":"2025-09-15T14:38:40.374Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28608167,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-20T16:10:39.856Z","status":"ssl_error","status_checked_at":"2026-01-20T16:10:39.493Z","response_time":117,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["hashicorp-vault","vault-plugin"],"created_at":"2026-01-17T11:15:03.285Z","updated_at":"2026-01-20T18:09:53.050Z","avatar_url":"https://github.com/statnett.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# vault-plugin-auth-jwt-auto-roles\n\nA Vault plugin to automatically authenticate with all roles matching a JWT (or\nOIDC) token, and grant access to the union of matching roles' policies.\n\n**Problem**: The [builtin _jwt_ auth\nplugin](https://github.com/hashicorp/vault-plugin-auth-jwt) requires a role-name\nto be specified during authentication. When authenticated, access is only\ngranted based on the policies of that single role. Even though the JWT satisfies\nmultiple roles' bound claims. Thus, multiple logins with different role names\nare required when policies are split across multiple roles, resulting in\nmultiple tokens which cannot be used interchangeably.\n\n**Solution**: The _jwt-auto-roles_ plugin automatically determines which roles'\nbound claims a JWT matches. It grants access to the union of all the matching\nroles' policies. Thus a single login is sufficient to get a token with combined\naccess, with the JWT as the sole login parameter.\n\n## Working Details\n\nThe plugin currently relies on the builtin _jwt_ plugin for JWT verification and\npolicy configuration. It simply determines the roles matching an incoming JWT's\nclaims, tries to login to a mount of the builtin _jwt_ plugin for each role, and\ngrants access to the union of policies returned by the builtin _jwt_ plugin\nmount.\n\n## Usage\n\nDownload and unzip a\n[release](https://github.com/statnett/vault-plugin-auth-jwt-auto-roles/releases)\nof the plugin and place it in the [plugin\ndirectory](https://developer.hashicorp.com/vault/docs/configuration#plugin_directory).\n\n[Register](https://developer.hashicorp.com/vault/docs/commands/plugin/register)\nthe plugin:\n\n`vault plugin register -sha256=\u003cbinary sha\u003e auth vault-plugin-auth-jwt-auto-roles`\n\nEnable the plugin at a specific mount path (e.g. `jwt-auto-roles`):\n\n`vault auth enable -path=jwt-auto-roles vault-plugin-auth-jwt-auto-roles`\n\nFor the plugin to be able to determine matching roles, it must be configured\nwith the host name and mount point of a builtin _jwt_ plugin mount, along with\nall its roles and their bound claims:\n\n`vault write auth/jwt-auto-roles/config @config.json`\n\n```json5\n// config.json\n{\n  \"jwt_auth_host\": \"https://vault.org.com\",\n  \"jwt_auth_path\": \"jwt\",\n  \"user_claim\": \"user_email\", // optional, generated based on policies and namespace otherwise\n  \"roles\": {\n    \"role-a\": {\n      \"project_path\": [\"foo/bar\"]\n    },\n    \"role-b\": {\n      \"branch\": [\"main\", \"master\"]\n    }\n  }\n}\n```\n\nThen login as with the builtin _jwt_ auth, although without the role parameter:\n\n`vault write auth/jwt-auto-roles/login jwt=$jwt`\n\n## Future work\n\nThe plugin could be configured with policies directly, instead of role names,\nand not rely on the builtin _jwt_ plugin for token verification. Although\nsimpler to configure, security guarantees will no longer be delegated to\nHashiCorp.\n\nThere is a also [an upstream issue](https://github.com/hashicorp/vault/issues/23279)\nto get this implemented in the official [_jwt_ plugin](https://github.com/hashicorp/vault-plugin-auth-jwt), obsoleting this plugin.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fstatnett%2Fvault-plugin-auth-jwt-auto-roles","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fstatnett%2Fvault-plugin-auth-jwt-auto-roles","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fstatnett%2Fvault-plugin-auth-jwt-auto-roles/lists"}