Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [jakartaee-platform-dev] [es-dev] Moving MicroProfile JWT to Jakarta Security?

+1 on what David said!
We should not spend time copying and pasting from one spec to another as our end users are using both technologies together. Having two similar things in both places does not bring any additional value but confusion. We should focus our limited resources on the area that MicroProfile and Jakarta EE have not covered. Jakarta EE and MicroProfile should work together as a unit to gain more popularity and become more and more successful.


On Fri, Nov 4, 2022 at 9:47 PM David Blevins <dblevins@xxxxxxxxxxxxx> wrote:
We could also go work on MP JWT and include that in our implementations?
On Nov 4, 2022, at 12:12 PM, arjan tijms <arjan.tijms@xxxxxxxxx> wrote:


In Jakarta Security we had long ago planned to include a JWT authentication mechanism. Some prototypes from around 2016 are still testimony to that.

Meanwhile, MicroProfile has specified JWT, and a couple of implementations of it (such as Payara, OmniFaces and SmallRye) are internally based on Jakarta Security.

We have discussed moving or copying MP specs to EE before, but nothing concrete has been established. Therefore I wonder how to proceed here. 

Do we copy over the MP JWT spec to a section in Jakarta Security and somehow keep them in sync?

Or do we reference the MP JWT spec from the Jakarta Security spec with text like: a compliant implementation should provide an authentication mechanism that behaves exactly like MP JWT with the following differences…

Or something else?


Kind regards,
Arjan Tijms

es-dev mailing list
To unsubscribe from this list, visit

jakartaee-platform-dev mailing list
To unsubscribe from this list, visit


Back to the top