Before API Management passes a request on to the back end, this policy confirms the JWT has the expected issuer, audience and claims.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains validate-jwt in context, with comparison tables and the common traps.
Terms in this definition
- API Management
Azure's API gateway, where policies like rate limits, quotas, ip-filter and validate-jwt are defined once and apply to every API. Production VNet injection is offered in the Premium tier.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- JWT
Compact, digitally signed token format. The Microsoft identity platform issues its access and ID tokens this way, and clients send them to REST APIs.
- Issuer
A field on a point-to-site gateway using Entra ID, set to the Secure Token Service URL https://sts.windows.net/{TenantID}/ including the final slash. It is neither the Graph nor the login URL.
- Audience
Setting on a point-to-site VPN gateway using Microsoft Entra ID authentication; it contains the app ID of the Azure VPN Client or of a custom app. Only a single Audience value is allowed per gateway.
Related terms
- Azure AD B2C
Identity platform for customer-facing apps; since 1 May 2025 new customers can't buy it and are directed to its successor, Microsoft Entra External ID. Tokens it issues can be checked by API Management's
validate-jwtpolicy via its OpenID configuration. - validate-azure-ad-token
An inbound API Management policy built specifically for Microsoft Entra tokens, checking the JWT's tenant, client application IDs, audiences and claims; a specialised option instead of validate-jwt.