Skip to content

W-24016354 Model Wallets 9/1 Release - #564

Open
valkyrie69 wants to merge 13 commits into
W-23753039-EME-08-R2-dmfrom
W-24016354-model-wallets-vh
Open

W-24016354 Model Wallets 9/1 Release#564
valkyrie69 wants to merge 13 commits into
W-23753039-EME-08-R2-dmfrom
W-24016354-model-wallets-vh

Conversation

@valkyrie69

Copy link
Copy Markdown
Contributor

No description provided.

@valkyrie69
valkyrie69 requested a review from a team as a code owner August 27, 2026 23:06
@valkyrie69 valkyrie69 self-assigned this Aug 27, 2026
@valkyrie69 valkyrie69 added the DO NOT MERGE Don't merge! label Aug 27, 2026
Comment thread modules/ROOT/pages/exp-model-wallets-manage.adoc Outdated
+
For more information, see xref:exp-home-start.adoc#permissions[Enhanced Experience Permissions].

Organizations without an IdP configured can't use model wallets. Those organizations continue to use existing access methods.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Organizations without an IdP configured can't use model wallets. Those organizations continue to use existing access methods.
Organizations without an IdP configured can't use model wallets.

I don't think necessary.

[[apply-jwt-validation-to-a-model-proxy]]
== Apply a JWT Validation Policy to a Model Proxy

A model wallet matches the client ID and JWT claims in a request to the wallet's configuration. The JWT Validation policy on the model proxy validates the token from your IdP first. Apply the policy on each model proxy that callers reach through the wallet. Apply the policy from the model proxy, not from *Model Wallets*.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
A model wallet matches the client ID and JWT claims in a request to the wallet's configuration. The JWT Validation policy on the model proxy validates the token from your IdP first. Apply the policy on each model proxy that callers reach through the wallet. Apply the policy from the model proxy, not from *Model Wallets*.
A model wallet matches the client ID and JWT claims in a request to the wallet's configuration. The JWT Validation policy to the model proxy validates the token from your IdP first. Apply the policy to each model proxy that callers reach through the wallet. Apply the policy from the model proxy, not from *Model Wallets*.

. Configure the policy to validate tokens from your IdP, including the JWT origin and the JSON Web Key Set (JWKS) URL or signing key. For configuration parameters, see xref:gateway::policies-included-jwt-validation.adoc[JWT Validation policy].
. Select *Apply Policy*.

Repeat the JWT Validation policy steps for each model proxy that callers reach through the wallet.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It might be worth it to mention that you could just add an automated policy instead of configuring each individual policy.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Admittidly, my understanding of automatic or global policies in minimal in EME, maybe @luanamulesoft could help.

@valkyrie69
valkyrie69 changed the base branch from latest to W-23753039-EME-08-R2-dm August 28, 2026 20:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

DO NOT MERGE Don't merge!

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants