Trait Claims
pub trait Claims:
Ephemeral
+ DeserializeOwned
+ Send
+ Sync
+ 'static {
// Required methods
fn sub(&self) -> &str;
fn iat(&self) -> u64;
fn iss(&self) -> Option<&str>;
fn preferred_username(&self) -> Option<&str>;
}Expand description
The contract that all JWT claims types must fulfill.
Implement this trait (along with Ephemeral) on your own struct to use
it with crate::TokenValidator. The method names mirror the standard JWT
claim names defined in RFC 7519.
§Required methods
| Method | JWT claim | Description |
|---|---|---|
sub | sub | Subject — who the token represents |
iat | iat | Issued-at timestamp (seconds since Unix epoch) |
iss | iss | Issuer — who issued the token |
preferred_username | preferred_username | Human-readable username (OIDC extension) |
The exp claim is provided via the Ephemeral supertrait.
§Example
See Ephemeral for a complete implementation example.
Required Methods§
fn sub(&self) -> &str
fn sub(&self) -> &str
The subject of the token (sub claim) — identifies who the token
represents, typically a user ID or service account identifier.
fn iss(&self) -> Option<&str>
fn iss(&self) -> Option<&str>
The issuer of the token (iss claim), or None if the claim is
absent. Used to verify the token came from the expected identity
provider.
fn preferred_username(&self) -> Option<&str>
fn preferred_username(&self) -> Option<&str>
The human-readable username from the preferred_username OIDC claim,
or None if the claim is absent. Not present in all token types —
machine-to-machine tokens typically omit it.
Dyn Compatibility§
This trait is not dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety", so this trait is not object safe.