Authentication
canton-deploy sends a JWT with every Ledger, Admin, and JSON API call. The token is resolved in this order:
--tokenCANTON_DEPLOY_TOKEN- config
token - config
oauth2(OAuth2 client credentials; the client secret is read from an environment variable, never from config) - config
tokenCommand(a shell command whose stdout is the token) - config
tokenFile - LocalNet development HMAC (network name
localnetonly)
LocalNet​
On a network named localnet, canton-deploy mints a development HMAC JWT (unsafe secret, user ledger-api-user) when no other source is configured.
The LocalNet HMAC token is a development convenience for a local sandbox only. Other networks need an explicit JWT.
OAuth2 Client Credentials​
For validators behind an OAuth2 provider such as Auth0, canton-deploy can fetch the token itself:
oauth2: {
tokenUrl: 'https://YOUR_TENANT.auth0.com/oauth/token',
clientId: 'YOUR_M2M_CLIENT_ID',
clientSecretEnv: 'DEVNET_OAUTH_CLIENT_SECRET',
audience: 'https://your-ledger-api-audience',
},
export DEVNET_OAUTH_CLIENT_SECRET='...'
dpm canton-deploy token --decode --network devnet
Tokens are cached in-process and refreshed when expiry is within five minutes.
tokenCommand and tokenFile​
Use tokenCommand when the token comes from another tool, such as Vault or a script:
tokenCommand: './scripts/get-devnet-token.sh',
Use tokenFile to read the token from a file:
tokenFile: '.devnet-token',
MainNet JWTs often come from tokenCommand.
Inspect the Resolved Token​
dpm canton-deploy token --network localnet
dpm canton-deploy token --decode --network devnet
dpm canton-deploy token --show --network devnet
token --decode shows the resolved source (oauth2, tokenCommand, and so on).