> For the complete documentation index, see [llms.txt](https://docs.jetadmin.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.jetadmin.io/access-and-sharing/authentication-and-sso/choose-an-authentication-method/token-based-authentication.md).

# Token-based authentication

Use this integration checklist when your application already has a custom authentication flow or needs to pass a user's identity to an API.

There is no single token configuration that applies to every provider. Confirm the supported integration path before implementation.

## Choose the intended behavior

| Need                                    | Related guide                                                                                                      |
| --------------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| Sign users in through an OAuth provider | [Custom SSO OAuth 2.0](/access-and-sharing/authentication-and-sso/sign-in-sign-up/custom-sso-oauth-2.0.md)         |
| Make API requests with an SSO token     | [API calls with SSO token](/access-and-sharing/authentication-and-sso/sign-in-sign-up/api-calls-with-sso-token.md) |
| Authenticate users with Xano            | [Xano Auth](/access-and-sharing/authentication-and-sso/choose-an-authentication-method/xano-auth.md)               |

The current External Authentication selector also includes **Custom authentication**. Its configuration must match the actual identity service and the fields in its setup form.

## Define and test the contract

Document the token issuer, intended API or audience, expiration behavior, identity mapping, and how the API validates requests. The API must decide whether that identity may perform the requested action on the requested record.

Test missing, invalid, expired, and wrong-user credentials as well as a successful request. Check that signing out and removing access have the behavior your application requires.

Do not place production tokens in example URLs, screenshots, prompts, or shared logs. For application data access, follow [Restrict access to records](/access-and-sharing/app-and-data-permissions/record-access.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.jetadmin.io/access-and-sharing/authentication-and-sso/choose-an-authentication-method/token-based-authentication.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
