Skip to content
This repository was archived by the owner on Feb 12, 2022. It is now read-only.
This repository was archived by the owner on Feb 12, 2022. It is now read-only.

Validate token in the webhook #1

@tachyons

Description

@tachyons
  • The token was sent in the HTTP Authorization header with “Bearer” scheme
  • The token is valid JSON that conforms to the JWT standard (see references)
  • The token contains an issuer claim with value of https://api.botframework.com
  • The token contains an audience claim with a value equivalent to your bot’s Microsoft App ID.
  • The token has not yet expired. Industry-standard clock-skew is 5 minutes.
  • The token has a valid cryptographic signature with a key listed in the OpenId keys document retrieved in step 1, above.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions