Downstream Authorization
Pattern for verifying ZeroID JWTs in downstream services — verify() for local fast checks, session() for revocation-aware checks, then extract claims before calling Shield.
What A Downstream Service Should Verify
Fetch the JWKS
GET /.well-known/jwks.jsonClaims That Usually Matter Most
Claim
How To Use It
Typical Authorization Patterns
Scope-Based Checks
Identity-Type Checks
Delegation-Aware Checks
Trust-Level Checks
Example Decision Logic
Introspection vs Local Verification
Local Verification
Introspection
Highflame Integration Pattern
What's Next?
Last updated