Skip to main content
The router examples require application-owned identityFromVerifiedClaims and authorizeOwnedResource functions. Resolve only verified credentials; atomically bind new sessions and deny unknown/foreign resources. See authenticated hosting. Authentication or role checks alone are insufficient.

Overview

Agentium provides built-in JWT authentication and RBAC middleware for the Express transport layer. Configure authentication, RBAC, and mandatory host identity/resource authorization together.

Quick Start

JWT Configuration

Requires: npm install jsonwebtoken

RBAC Configuration

Built-in Scope Map

Token Format

Wildcard scopes do not bypass resource authorization. Unknown routes are denied until explicitly registered in the RBAC route map.