能否配置Xero返回的JWT中aud字段添加自定义受众值?
Short Answer
Unfortunately, you can’t configure Xero to modify the aud field in its OAuth2 access tokens—it’s hardcoded as the single string https://identity.xero.com/resources, and there’s no way to add custom values or convert it to an array. Xero doesn’t expose any settings in the developer portal, API parameters, or documented workflows to adjust this claim.
Detailed Breakdown
Let’s unpack why this limitation exists and what your options are:
- Xero’s Token Standards: Xero’s OAuth2 implementation locks the
audclaim to identify its own identity resource server. This is a fixed part of their token format, and there’s no official support for overriding or extending it through app configurations, scopes, or request parameters. - Fauna AccessProvider Mismatch: Fauna’s AccessProvider expects the JWT’s
audclaim to include the audience value you defined in your AccessProvider instance. Since Xero can’t adjust this claim directly, you’ll need a workaround to bridge the gap.
Practical Workarounds to Integrate Xero with Fauna
Here are actionable solutions to make this integration work:
Build a Token Proxy Service
- Create a lightweight intermediary that accepts Xero’s access token, validates it using Xero’s public keys, then generates a new JWT that includes your Fauna audience in the
audfield. You can use libraries likejsonwebtoken(Node.js) orPyJWT(Python) to craft this modified token. - Your frontend would send the Xero token to this proxy, receive the adjusted JWT, and use that to authenticate with Fauna.
- Create a lightweight intermediary that accepts Xero’s access token, validates it using Xero’s public keys, then generates a new JWT that includes your Fauna audience in the
Route Requests Through Your Backend
- Instead of letting the frontend call Fauna directly with Xero’s token, handle the flow via your backend:
- Frontend sends Xero’s access token to your backend.
- Backend validates the token by fetching user details from Xero’s API to confirm its validity.
- Backend uses its own Fauna server key to make requests on behalf of the user, applying role-based access controls based on the Xero user’s identity.
- Instead of letting the frontend call Fauna directly with Xero’s token, handle the flow via your backend:
Use Xero’s Other Claims for Fauna Authorization
- While Fauna’s AccessProvider prioritizes the
audclaim, you can configure it to trust Xero’s issuer and use other claims (likesubfor the user ID) to map to Fauna roles. This skips theaudrequirement entirely and relies on user identity claims for authorization.
- While Fauna’s AccessProvider prioritizes the
Verification Notes
To confirm Xero’s token structure doesn’t support custom aud values:
- Decode your Xero access token using a local JWT decoder—you’ll see the
audfield is always the fixed string. - Check Xero’s official OAuth2 docs and developer community threads; there are no mentions of modifying the
audclaim for third-party integrations.
内容的提问来源于stack exchange,提问作者Alex Nitta

