Signed-in users and per-user tools
Issue a host JWT so the assistant knows who the user is and your API only returns that user's data.
Goal
A logged-in shopper asks “my orders” → list_orders is called with the user’s identity → your API returns only their orders.
Pieces
- Your backend signs a JWT for the logged-in user:
sub(your user id), optionalname,email,plan,exp(short, for example 15 minutes),issandaudif you want them enforced. HS256 with a shared secret, or RS256/ES256 with a JWKS endpoint. - Dashboard → Settings → End-user auth: mode HS256 (pick the secret you stored under Secrets) or JWKS URL; issuer and audience.
- Tool
list_orderswith Acts as the end user on, headerX-User-Token(or whatever your API expects). The runtime forwards the user’s JWT in that header on every call. - SDK:
await client.authenticate(token: jwt, onTokenExpired: fetchFreshJwt).
Steps
- Store the HS256 secret: Secrets → New secret
user_jwt_hs256. - Settings → End-user auth → HS256, choose the secret, set issuer/audience.
- In the app, after your own login, call
authenticate. On logout callclient.logout(). - On your API, verify
X-User-Tokenexactly as you verify your own sessions, and scope queries bysub.
Verify
- Users page: the user appears as identified with
planfrom the claim. - Preview cannot impersonate a user; test in the app: “my orders” → tool call → only that user’s orders.
- Expire the token: the runtime returns 4403, the SDK calls
onTokenExpired, reconnects, and the conversation continues.
Notes
- Context keys marked sensitive (for example an internal customer id) reach tools but never the model.
- The end user’s traits (
name,plan) are stored for the dashboard; they reach the prompt only if you also put them in context.