# Required Claim Mapper Permissions for Worker Service

**URL:** <https://community.temporal.io/t/required-claim-mapper-permissions-for-worker-service/14972>\
**Category:** Server Deployment\
**Tags:** auth\
**Created:** [November 4, 2024, 10:28pm UTC](https://community.temporal.io/t/required-claim-mapper-permissions-for-worker-service/14972 "2024-11-04T22:28:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aaron\_Huntress](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/aaron_huntress/32/6254_2.png) [@Aaron\_Huntress](https://community.temporal.io/u/Aaron_Huntress)\
**Post date:** [November 4, 2024, 10:28pm UTC](https://community.temporal.io/t/required-claim-mapper-permissions-for-worker-service/14972/1 "2024-11-04T22:28:55Z")

</div>

We’ve build a custom claim mapper (all custom) and a customized authorizer (uses much of the default authorizer), and it’s a bit unclear what permissions are actually required by the worker service.

I initially thought restricting the worker service to the `temporal-system` namespace would be sufficient, but now I’m seeing errors where the worker service is failing auth checks on the `default` namespace against the `temporal-sys-per-ns-tq` task queue.

Is there some documentation regarding minimal permissions for the worker service or even other services for that matter?

---

<div class="post-metadata">

**Author:** ![tihomir](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/tihomir/32/6580_2.png) [@tihomir](https://community.temporal.io/u/tihomir)\
**Post date:** [November 4, 2024, 10:59pm UTC](https://community.temporal.io/t/required-claim-mapper-permissions-for-worker-service/14972/2 "2024-11-04T22:59:35Z")

</div>

Worker service would require `System: RoleAdmin` claim.  
Note that since release 1.20 you can set up internal-frontend service where worker service can bypass your custom claims mapper and treat it as an internode service, see release notes [Release v1.20.0 · temporalio/temporal · GitHub](https://github.com/temporalio/temporal/releases/tag/v1.20.0)

---

<div class="post-metadata">

**Author:** ![Aaron\_Huntress](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/aaron_huntress/32/6254_2.png) [@Aaron\_Huntress](https://community.temporal.io/u/Aaron_Huntress)\
**Post date:** [November 5, 2024, 1:40pm UTC](https://community.temporal.io/t/required-claim-mapper-permissions-for-worker-service/14972/3 "2024-11-05T13:40:14Z")

</div>

Thank you, @tihomir!

Is the same true for application workers?

---

<div class="post-metadata">

**Author:** ![Ujala\_Singh](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/ujala_singh/32/5728_2.png) [@Ujala\_Singh](https://community.temporal.io/u/Ujala_Singh)\
**Post date:** [May 30, 2025, 12:35pm UTC](https://community.temporal.io/t/required-claim-mapper-permissions-for-worker-service/14972/4 "2025-05-30T12:35:04Z")

</div>

@Aaron_Huntress What all environments needs to be set on worker service for Authentication with frontend service? I am also facing the same issue since I have added the auth:

```auto
authorization:
    jwtKeyProvider:
      keySourceURIs:
        - https://mydomain/auth/realms/default/protocol/openid-connect/certs
      refreshInterval: "1m"
    permissionsClaimName: "permissions"
    authorizer: default
    claimMapper: default

```
