Skip to main content

Shield Authentication

SDD Classification: L3-Technical Authority: Engineering Team Review Cycle: Quarterly
This document covers Shield’s authentication mechanisms including email/password login, JWT token management, OAuth 2.0 flows, and session handling.

Authentication Overview


Email/Password Authentication

Login Endpoint

Success Response

Login Flow Implementation


JWT Token Structure

Access Token Claims

Token Properties

Token Generation


Token Refresh

Refresh Endpoint

Refresh Flow

Refresh Implementation


Token Revocation

Revoke Endpoint

Revoke All Sessions

Implementation


Public Key Distribution

JWKS Endpoint

Response

Key Rotation


Rate Limiting

Limits by Endpoint

Implementation


Session Security

Session Storage


Error Codes



Document Status: Complete Version: 2.0