# Authorization, Untrusted workflow creation and namespace authentication

**URL:** <https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632>\
**Category:** Community Support\
**Tags:** auth\
**Created:** [September 15, 2020, 11:05pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632 "2020-09-15T23:05:09Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![macsinte](https://avatars.discourse-cdn.com/v4/letter/m/7993a0/32.png) [@macsinte](https://community.temporal.io/u/macsinte)\
**Post date:** [September 15, 2020, 11:05pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/1 "2020-09-15T23:05:09Z")

</div>

Hello all,

I have a question on the authorization around Temporal that’s existent at this point.

1. Can we contribute to anything ASAP and/or use anything existent that would prevent tenants from seeing/accessing/subscribing to each other’s namespaces?

At the moment there’s nothing that prevents people from doing the above (as far as I saw). We don’t really want to have different namespaces (workflows, workers, etc.) have access to each other, see their workflows’ data, etc.

In addition (correct me if I am wrong please), I saw that there is no mechanism to authenticate the registration to a task queue/task list.

Thank you,

Marius

---

<div class="post-metadata">

**Author:** ![ryland](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/ryland/32/11_2.png) [@ryland](https://community.temporal.io/u/ryland)\
**Post date:** [September 18, 2020, 4:18pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/3 "2020-09-18T16:18:24Z")

</div>

Hey, sorry it took a while to get back to you. The direct answer is that neither Cadence or Temporal support any form of fine grained access control or authentication out of the box. Temporal does support mutual TLS over GRPC which actually does provide a means to achieve secure namespace isolation. I honestly am not educated enough to explain how this will work at the lowest level, but the gist is that you use custom TLS certs for different users/namespaces.

I’ll let Max chime in if there is anything that you can contribute.

---

<div class="post-metadata">

**Author:** ![junjieli](https://avatars.discourse-cdn.com/v4/letter/j/779978/32.png) [@junjieli](https://community.temporal.io/u/junjieli)\
**Post date:** [March 25, 2021, 11:42pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/4 "2021-03-25T23:42:47Z")

</div>

Hi @ryland or @maxim, I’m wondering if there is any update on namespace level access control? Seems this is an important piece missing.

---

<div class="post-metadata">

**Author:** ![ryland](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/ryland/32/11_2.png) [@ryland](https://community.temporal.io/u/ryland)\
**Post date:** [March 25, 2021, 11:56pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/5 "2021-03-25T23:56:15Z")

</div>

We’ve supported both authentication and authorization for a few months now!

> **[Temporal Server security | Temporal](https://docs.temporal.io/docs/server-security/)**
>
> Overview

Let me know if you have any other questions.

---

<div class="post-metadata">

**Author:** ![junjieli](https://avatars.discourse-cdn.com/v4/letter/j/779978/32.png) [@junjieli](https://community.temporal.io/u/junjieli)\
**Post date:** [March 26, 2021, 6:18am UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/6 "2021-03-26T06:18:30Z")

</div>

Thanks @ryland ! After reading the page, I’m still a little confused as how this works. How do I set up who has access to a namespace and how to use the temporal sdk to provide the credential? It would be great if you have any java examples.

---

<div class="post-metadata">

**Author:** ![ryland](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/ryland/32/11_2.png) [@ryland](https://community.temporal.io/u/ryland)\
**Post date:** [March 26, 2021, 5:05pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/7 "2021-03-26T17:05:32Z")

</div>

@SergeyBykov

---

<div class="post-metadata">

**Author:** ![SergeyBykov](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/sergeybykov/32/335_2.png) [@SergeyBykov](https://community.temporal.io/u/SergeyBykov)\
**Post date:** [March 26, 2021, 6:30pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/8 "2021-03-26T18:30:28Z")

</div>

We have a Go sample - [customization-samples/extensibility/authorizer at master · temporalio/customization-samples · GitHub](https://github.com/temporalio/customization-samples/tree/master/extensibility/authorizer) of how one can implement authorization logic. Temporal server by itself does not impose any authorization. It is the job of the pluggable Authorizer and ClaimMapper components. ClaimMapper is responsible for translating identity information of the caller, from the TLS cert and/or JWT token, into a set of role claims that Authorizer uses as input for authorization decisions.

---

<div class="post-metadata">

**Author:** ![poojabhutada](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/poojabhutada/32/3372_2.png) [@poojabhutada](https://community.temporal.io/u/poojabhutada)\
**Post date:** [February 21, 2022, 8:14am UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/9 "2022-02-21T08:14:22Z")

</div>

Hi,  
I would like to understand about how the same can be achieved using Java SDK. It would be really helpful to see some java sample on that, as the same is not clear through documentation.

---

<div class="post-metadata">

**Author:** ![tihomir](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tihomir/32/6580_2.png) [@tihomir](https://community.temporal.io/u/tihomir)\
**Post date:** [February 21, 2022, 4:47pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/10 "2022-02-21T16:47:52Z")

</div>

Created Issue [Add Authorizer+Claims Mapper sample · Issue #234 · temporalio/samples-java · GitHub](https://github.com/temporalio/samples-java/issues/234)

---

<div class="post-metadata">

**Author:** ![poojabhutada](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/poojabhutada/32/3372_2.png) [@poojabhutada](https://community.temporal.io/u/poojabhutada)\
**Post date:** [February 22, 2022, 3:59am UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/11 "2022-02-22T03:59:34Z")

</div>

Thanks a lot for the help @tihomir. Will be waiting for the java sample.

---

<div class="post-metadata">

**Author:** ![poojabhutada](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/poojabhutada/32/3372_2.png) [@poojabhutada](https://community.temporal.io/u/poojabhutada)\
**Post date:** [February 28, 2022, 1:46pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/12 "2022-02-28T13:46:03Z")

</div>

@tihomir Is there any update on this? May I know the timelines for the same…if any…

---

<div class="post-metadata">

**Author:** ![tihomir](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tihomir/32/6580_2.png) [@tihomir](https://community.temporal.io/u/tihomir)\
**Post date:** [February 28, 2022, 1:47pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/13 "2022-02-28T13:47:21Z")

</div>

@poojabhutada i am planning to add sample this week

---

<div class="post-metadata">

**Author:** ![poojabhutada](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/poojabhutada/32/3372_2.png) [@poojabhutada](https://community.temporal.io/u/poojabhutada)\
**Post date:** [February 28, 2022, 1:52pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/14 "2022-02-28T13:52:25Z")

</div>

Thanks @tihomir for the update…!

---

<div class="post-metadata">

**Author:** ![tihomir](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tihomir/32/6580_2.png) [@tihomir](https://community.temporal.io/u/tihomir)\
**Post date:** [March 3, 2022, 9:28pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/15 "2022-03-03T21:28:58Z")

</div>

@poojabhutada was looking at this and not sure if it fits in our java samples repo, probably is better suited for a small demo app which would indeed be nice to have.  
Reason is that we already as shown [here](https://github.com/temporalio/samples-server/tree/main/extensibility/authorizer) have a server sample that shows how to set up claims mapper and authorizer, and we also have [this](https://docs.temporal.io/docs/java/how-to-provide-an-authorization-token-in-java/) docs page that shows how to provide auth tokens via java sdk.  
I think with this you would just need to generate your JWT tokens for example and start using it.

---

<div class="post-metadata">

**Author:** ![poojabhutada](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/poojabhutada/32/3372_2.png) [@poojabhutada](https://community.temporal.io/u/poojabhutada)\
**Post date:** [March 4, 2022, 4:06am UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/16 "2022-03-04T04:06:22Z")

</div>

@tihomir Do you mean that we need to write custom authorizer and claimmapper in Golang in order to manage the incoming calls through JWT token and then deploy the custom Temporal server image on our own?

---

<div class="post-metadata">

**Author:** ![tihomir](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tihomir/32/6580_2.png) [@tihomir](https://community.temporal.io/u/tihomir)\
**Post date:** [March 4, 2022, 4:30am UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/17 "2022-03-04T04:30:56Z")

</div>

You don’t have to write a custom one, you can use the [defaults](https://github.com/temporalio/temporal/tree/master/common/authorization) based on JWT. You can configure it, in case you are using docker compose yml:

```auto
global:
  authorization:
    jwtKeyProvider:
      keySourceURIs:
      - <source url>
      refreshInterval: 1m
    authorizer: default
    claimMapper: default

```

or if docker image, via env vars, for example:

`TEMPORAL_JWT_KEY_SOURCE1=<source url>`  
`TEMPORAL_AUTH_AUTHORIZER=default`  
`TEMPORAL_AUTH_CLAIM_MAPPER=default`

Where `<source url>` is an HTTP endpoint that hosts your public keys used to sign tokens (JWK format).  
Your tokens permissions claim is used to determine what client can do.

You can provide token supplier via WorkflowServiceStubsOptions as shown in link.

---

<div class="post-metadata">

**Author:** ![poojabhutada](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/poojabhutada/32/3372_2.png) [@poojabhutada](https://community.temporal.io/u/poojabhutada)\
**Post date:** [March 7, 2022, 3:49am UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/18 "2022-03-07T03:49:37Z")

</div>

Ok @tihomir . Thanks a lot for the clarification, will check further on this.

---

<div class="post-metadata">

**Author:** ![Ruchir](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/ruchir/32/6141_2.png) [@Ruchir](https://community.temporal.io/u/Ruchir)\
**Post date:** [April 20, 2022, 10:01am UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/19 "2022-04-20T10:01:55Z")

</div>

Hi @tihomir

> [@tihomir](#):
>
> and we also have [this](https://docs.temporal.io/docs/java/how-to-provide-an-authorization-token-in-java/?_ga=2.231277273.776042735.1650254452-1781121356.1643869734) docs page that shows how to provide auth tokens via java sdk.

follow up query on this point, can a function be passed as a `AuthorizationTokenSupplier` , for eg:

```auto
AuthorizationTokenSupplier tokenSupplier = () -> return restTemplate.get("http-endpoint-which-returns-jwt-tokens");

```

also, in one scenario, i’ll be getting the token from the caller of workflow, is it possible to provide that token in the above supplier?

---

<div class="post-metadata">

**Author:** ![pradnya.bhalekar](https://avatars.discourse-cdn.com/v4/letter/p/f4b2a3/32.png) [@pradnya.bhalekar](https://community.temporal.io/u/pradnya.bhalekar)\
**Post date:** [June 20, 2022, 1:55pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/21 "2022-06-20T13:55:28Z")

</div>

> [@tihomir](#):
>
> Your tokens permissions claim is used to determine what client can do.

How should the token permissions look like? plz share sample

---

<div class="post-metadata">

**Author:** ![kmahyyg](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/kmahyyg/32/4187_2.png) [@kmahyyg](https://community.temporal.io/u/kmahyyg)\
**Post date:** [August 18, 2023, 3:16pm UTC](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632/22 "2023-08-18T15:16:12Z")

</div>

Please document this in [Temporal Cluster deployment guide | Temporal Documentation](https://docs.temporal.io/cluster-deployment-guide)  
And also: [Temporal Cluster configuration reference | Temporal Documentation](https://docs.temporal.io/references/configuration#global)

I can’t find any docs mentioned this, now I reviewed the config template under /docker/config\_template.yaml . This is really unfriendly for bare-metal users.

I just searched a lot… and finally found here after several hours…

[Next page](https://community.temporal.io/t/authorization-untrusted-workflow-creation-and-namespace-authentication/632.md?page=2)
