JBoss EAP Elytron OIDC bearer token authentication fails with AWS Cognito access tokens (ELY23051: Invalid bearer token)

Solution In Progress - Updated -

Issue

Bearer-only REST API authentication configured with the elytron-oidc-client subsystem fails when validating access tokens issued by AWS Cognito. OpenID Connect discovery, JWKS retrieval, and signing key resolution all complete successfully, but the request is rejected with:

ELY23013: Failed verification of token: ELY23051: Invalid bearer token

This occurs even when the iss (issuer) claim matches the configured provider-url, the signing key (kid) is resolved correctly, and verify-token-audience is left at its default (false).

Environment

  • Red Hat JBoss Enterprise Application Platform (JBoss EAP):
    • 8.x
  • elytron-oidc-client subsystem
  • bearer-only secure-deployment
  • Identity Provider: AWS Cognito

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content