Signed-in users and per-user tools

Issue a host JWT so the assistant knows who the user is and your API only returns that user's data.

Goal

A logged-in shopper asks “my orders” → list_orders is called with the user’s identity → your API returns only their orders.

Pieces

  • Your backend signs a JWT for the logged-in user: sub (your user id), optional name, email, plan, exp (short, for example 15 minutes), iss and aud if you want them enforced. HS256 with a shared secret, or RS256/ES256 with a JWKS endpoint.
  • Dashboard → Settings → End-user auth: mode HS256 (pick the secret you stored under Secrets) or JWKS URL; issuer and audience.
  • Tool list_orders with Acts as the end user on, header X-User-Token (or whatever your API expects). The runtime forwards the user’s JWT in that header on every call.
  • SDK: await client.authenticate(token: jwt, onTokenExpired: fetchFreshJwt).

Steps

  1. Store the HS256 secret: Secrets → New secret user_jwt_hs256.
  2. Settings → End-user auth → HS256, choose the secret, set issuer/audience.
  3. In the app, after your own login, call authenticate. On logout call client.logout().
  4. On your API, verify X-User-Token exactly as you verify your own sessions, and scope queries by sub.

Verify

  • Users page: the user appears as identified with plan from the claim.
  • Preview cannot impersonate a user; test in the app: “my orders” → tool call → only that user’s orders.
  • Expire the token: the runtime returns 4403, the SDK calls onTokenExpired, reconnects, and the conversation continues.

Notes

  • Context keys marked sensitive (for example an internal customer id) reach tools but never the model.
  • The end user’s traits (name, plan) are stored for the dashboard; they reach the prompt only if you also put them in context.

Last updated 2026-09-28 · Report an issue with this page