JBoss EAP Elytron OIDC bearer token authentication fails with AWS Cognito access tokens (ELY23051: Invalid bearer token)
Issue
Bearer-only REST API authentication configured with the elytron-oidc-client subsystem fails when validating access tokens issued by AWS Cognito. OpenID Connect discovery, JWKS retrieval, and signing key resolution all complete successfully, but the request is rejected with:
ELY23013: Failed verification of token: ELY23051: Invalid bearer token
This occurs even when the iss (issuer) claim matches the configured provider-url, the signing key (kid) is resolved correctly, and verify-token-audience is left at its default (false).
Environment
- Red Hat JBoss Enterprise Application Platform (JBoss EAP):
- 8.x
- elytron-oidc-client subsystem
- bearer-only secure-deployment
- Identity Provider: AWS Cognito
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.