Bring Your Own Auth (BYOA) is an enterprise feature. Contact us in Slack or at dynamic@fireblocks.com to enable it.
Issue a Dynamic-specific JWT from your auth provider, separate from your application’s normal access token, so the token Dynamic receives cannot be used to access resources on your own servers. See Bring Your Own Auth for the full recommendation.
Prerequisites
- BYOA configured in your Dynamic developer console (issuer, JWKS URL).
- Before this: create and initialize a Dynamic client (see Creating a Dynamic Client, Initializing the Dynamic Client).
- Your backend issues a JWT with at least
iss,sub, andexpclaims.
Usage
CallsignInWithExternalJwt with the JWT issued by your auth provider. Dynamic verifies the signature against your configured JWKS URL, validates the claims, and establishes a session.
Parameters
Dynamic derives the external user ID from the
sub claim in the JWT, so you do not pass it in.
Related
- Bring Your Own Auth: concepts, configuration, and JWT requirements.
- External auth step-up: issue elevated access tokens from your backend for sensitive actions.