# Temporal worker authorization roles

**URL:** <https://community.temporal.io/t/temporal-worker-authorization-roles/17503>\
**Category:** Community Support\
**Tags:** python-sdk, helm\
**Created:** [May 23, 2025, 7:48am UTC](https://community.temporal.io/t/temporal-worker-authorization-roles/17503 "2025-05-23T07:48:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![A\_T](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/a_t/32/6243_2.png) [@A\_T](https://community.temporal.io/u/A_T)\
**Post date:** [May 23, 2025, 7:48am UTC](https://community.temporal.io/t/temporal-worker-authorization-roles/17503/1 "2025-05-23T07:48:46Z")

</div>

I have been trying to authorize my worker by setting the role namespace:\*, somehow I feel the temporal server which is helm based is not interpreting the permissions correctly.

```auto
authorization:
      jwtKeyProvider:
        keySourceURIs:
          - https://login.microsoftonline.com/$tenant_id/discovery/v2.0/keys
        refreshInterval: 1m
      permissionsClaimName: roles
      authorizer: default
      claimMapper: default

```

on the worker side after authentication I get the following:

```auto
RuntimeError: Worker validation failed

Caused by:
    0: Namespace test was not found or otherwise could not be described: Status { code: PermissionDenied, message: "Request unauthorized.", details: b"\x08\x07\x12\x15Request unauthorized.\x1aJ\nHtype.googleapis.com/temporal.api.errordetails.v1.PermissionDeniedFailure", metadata: MetadataMap { headers: {"content-type": "application/grpc"} }, source: None }

```

Somehow I am not able to get this working by just following the documentation. Any assist is appreciated.

---

<div class="post-metadata">

**Author:** ![hferentschik](https://avatars.discourse-cdn.com/v4/letter/h/91b2a8/32.png) [@hferentschik](https://community.temporal.io/u/hferentschik)\
**Post date:** [May 23, 2025, 8:45am UTC](https://community.temporal.io/t/temporal-worker-authorization-roles/17503/2 "2025-05-23T08:45:32Z")

</div>

Hi,

Which documentation are you referring to and which namespace are you trying to connect to? The error message seems to imply you try to connect to the `test` namespace. Does this namespace exist?

–Hardy

---

<div class="post-metadata">

**Author:** ![A\_T](https://sea2.discourse-cdn.com/flex016/user_avatar/community.temporal.io/a_t/32/6243_2.png) [@A\_T](https://community.temporal.io/u/A_T)\
**Post date:** [May 23, 2025, 9:21am UTC](https://community.temporal.io/t/temporal-worker-authorization-roles/17503/3 "2025-05-23T09:21:41Z")

</div>

Hello,

> **[Temporal Platform security features | Temporal Platform Documentation](https://docs.temporal.io/self-hosted-guide/security)**
>
> Discover comprehensive security features of the Temporal Platform, including secure network communication with TLS and mTLS, robust authentication, customizable authorization, and single sign-on integration to protect your data and operations.

the namespace exists and on the azure side I assign test:\* role to the application and I already see it when I decode the returned token.
