Official CefasDB website

Authentication And Authorization - CefasDB Docs

CefasDB validates bearer tokens through JWKS and enforces operation and table scopes.

Documentation excerpt

Concepts: Authentication And Authorization

CefasDB can run open in a trusted development environment or validate bearer tokens against an identity provider. Production deployments should enable token validation and configure per-operation authorization scopes.

The server exposes flags for identity configuration:

JWKS URL. Expected issuer. Expected audience. Allowed clock skew.