Official CefasDB website
Authentication And Authorization - CefasDB Docs
CefasDB validates bearer tokens through JWKS and enforces operation and table scopes.
Documentation excerpt
Concepts: Authentication And Authorization
CefasDB can run open in a trusted development environment or validate bearer tokens against an identity provider. Production deployments should enable token validation and configure per-operation authorization scopes.
The server exposes flags for identity configuration:
JWKS URL. Expected issuer. Expected audience. Allowed clock skew.