Skip to main content

Claims

Trait Claims 

pub trait Claims:
    Ephemeral
    + DeserializeOwned
    + Send
    + Sync
    + 'static {
    // Required methods
    fn sub(&self) -> &str;
    fn iat(&self) -> u64;
    fn iss(&self) -> Option<&str>;
    fn preferred_username(&self) -> Option<&str>;
}
Expand description

The contract that all JWT claims types must fulfill.

Implement this trait (along with Ephemeral) on your own struct to use it with crate::TokenValidator. The method names mirror the standard JWT claim names defined in RFC 7519.

§Required methods

MethodJWT claimDescription
subsubSubject — who the token represents
iatiatIssued-at timestamp (seconds since Unix epoch)
ississIssuer — who issued the token
preferred_usernamepreferred_usernameHuman-readable username (OIDC extension)

The exp claim is provided via the Ephemeral supertrait.

§Example

See Ephemeral for a complete implementation example.

Required Methods§

fn sub(&self) -> &str

The subject of the token (sub claim) — identifies who the token represents, typically a user ID or service account identifier.

fn iat(&self) -> u64

The time the token was issued (iat claim), as seconds since the Unix epoch.

fn iss(&self) -> Option<&str>

The issuer of the token (iss claim), or None if the claim is absent. Used to verify the token came from the expected identity provider.

fn preferred_username(&self) -> Option<&str>

The human-readable username from the preferred_username OIDC claim, or None if the claim is absent. Not present in all token types — machine-to-machine tokens typically omit it.

Dyn Compatibility§

This trait is not dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety", so this trait is not object safe.

Implementors§