Skip to main content

Authentication

canton-deploy sends a JWT with every Ledger, Admin, and JSON API call. The token is resolved in this order:

  1. --token
  2. CANTON_DEPLOY_TOKEN
  3. config token
  4. config oauth2 (OAuth2 client credentials; the client secret is read from an environment variable, never from config)
  5. config tokenCommand (a shell command whose stdout is the token)
  6. config tokenFile
  7. LocalNet development HMAC (network name localnet only)

LocalNet​

On a network named localnet, canton-deploy mints a development HMAC JWT (unsafe secret, user ledger-api-user) when no other source is configured.

warning

The LocalNet HMAC token is a development convenience for a local sandbox only. Other networks need an explicit JWT.

OAuth2 Client Credentials​

For validators behind an OAuth2 provider such as Auth0, canton-deploy can fetch the token itself:

oauth2: {
tokenUrl: 'https://YOUR_TENANT.auth0.com/oauth/token',
clientId: 'YOUR_M2M_CLIENT_ID',
clientSecretEnv: 'DEVNET_OAUTH_CLIENT_SECRET',
audience: 'https://your-ledger-api-audience',
},
export DEVNET_OAUTH_CLIENT_SECRET='...'
dpm canton-deploy token --decode --network devnet

Tokens are cached in-process and refreshed when expiry is within five minutes.

tokenCommand and tokenFile​

Use tokenCommand when the token comes from another tool, such as Vault or a script:

tokenCommand: './scripts/get-devnet-token.sh',

Use tokenFile to read the token from a file:

tokenFile: '.devnet-token',

MainNet JWTs often come from tokenCommand.

Inspect the Resolved Token​

dpm canton-deploy token --network localnet
dpm canton-deploy token --decode --network devnet
dpm canton-deploy token --show --network devnet

token --decode shows the resolved source (oauth2, tokenCommand, and so on).