# Auth on Schema, invalid "Alg"

**URL:** <https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474>\
**Category:** GraphQL\
**Tags:** schema\
**Created:** [June 8, 2021, 4:30pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474 "2021-06-08T16:30:56Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marco\_Antonio](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/marco_antonio/32/8361_2.png) [@Marco\_Antonio](https://discuss.dgraph.io/u/Marco_Antonio)\
**Post date:** [June 8, 2021, 4:30pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474/1 "2021-06-08T16:30:56Z")

</div>

A simple User schema which expects a `sub` claim inside the token payload can be this one:

```auto
type User @auth(
    query: {
        rule: """
            query ($sub: String!){
                queryUser(filter: {id: {eq: $sub}}){
                    id
                    email
                    name
                    gender
                    birthdate
                }
            }
        """
    }
){
    id: String! @search(by: [hash]) @id
    email: String! @search(by: [fulltext])
    gender: String!
    age: String!
    name: String!
}

```

Using an external authority for user authentification, we may provide the following comment on the end of the `<schema>.graphql` file, including the `JWTURL`:

```auto
# Dgraph.Authorization {"VerificationKey":"", "Header":"Authorization", "JWTURL":"<External_auth_URL>", "Namespace":"", "Algo":"", "Audience":[<client_ID>, <application_ID>]}

```

By sending

```auto
curl -X POST localhost:8080/admin/schema --data-binary '@<schema>.graphql'

```

But, the response is:

```auto
{"errors":[{"message":"resolving updateGQLSchema failed because invalid jwt algorithm: found \"JWTURL\":\"<External_auth_URL>\",, but supported options are: S384,RS512,HS256,HS384,HS512,RS256 (Locations: [{Line: 3, Column: 4}])","extensions":{"code":"Error"}}]}

```

Am I parsing the `Dgraph.Authorization` wrong? I’m just following the documentation on: [https://dgraph.io/docs/graphql/authorization/authorization-overview/](https://dgraph.io/docs/graphql/authorization/authorization-overview/)

---

<div class="post-metadata">

**Author:** ![jdgamble555](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/jdgamble555/32/7503_2.png) [@jdgamble555](https://discuss.dgraph.io/u/jdgamble555)\
**Post date:** [June 8, 2021, 6:19pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474/2 "2021-06-08T18:19:17Z")

</div>

Did you replace “\<External\_auth\_URL\>” with an actual URL that validates this? It seems like the URL is your problem.

J

---

<div class="post-metadata">

**Author:** ![Marco\_Antonio](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/marco_antonio/32/8361_2.png) [@Marco\_Antonio](https://discuss.dgraph.io/u/Marco_Antonio)\
**Post date:** [June 8, 2021, 6:24pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474/3 "2021-06-08T18:24:50Z")

</div>

Yes, I did that. As far as I know, the URL is good, it is from AWS Cognito itself, which can be obtained by going to: `https://cognito-idp.<zone>.amazonaws.com/<client_id>/.well-known/jwks.json`.

---

<div class="post-metadata">

**Author:** ![jdgamble555](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/jdgamble555/32/7503_2.png) [@jdgamble555](https://discuss.dgraph.io/u/jdgamble555)\
**Post date:** [June 8, 2021, 6:32pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474/4 "2021-06-08T18:32:09Z")

</div>

In that “jwks.json” file, is there:

```auto
{
  "alg": "HS256",
}

```

with one of the options [S384,RS512,HS256,HS384,HS512,RS256] ?

J

---

<div class="post-metadata">

**Author:** ![Marco\_Antonio](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/marco_antonio/32/8361_2.png) [@Marco\_Antonio](https://discuss.dgraph.io/u/Marco_Antonio)\
**Post date:** [June 8, 2021, 6:33pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474/5 "2021-06-08T18:33:10Z")

</div>

yes, it is the option `RS256`.

---

<div class="post-metadata">

**Author:** ![jdgamble555](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/jdgamble555/32/7503_2.png) [@jdgamble555](https://discuss.dgraph.io/u/jdgamble555)\
**Post date:** [June 8, 2021, 6:36pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474/6 "2021-06-08T18:36:59Z")

</div>

Get rid of the “Algo” key in your schema and see what happens. Also, are you using **21.03**?

J

---

<div class="post-metadata">

**Author:** ![Marco\_Antonio](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/marco_antonio/32/8361_2.png) [@Marco\_Antonio](https://discuss.dgraph.io/u/Marco_Antonio)\
**Post date:** [June 8, 2021, 6:44pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474/7 "2021-06-08T18:44:44Z")

</div>

Sorry, when I made a issue earlier, there was a template for the version and specs, but it din’t show this time.

I’m using version 21.03, system Fedora 33, and good hardware.

When I remove the Algo key, the error persists. Using:

```auto
# Dgraph.Authorization {"VerificationKey":"", "Header":"Authorization", "JWTURL":"https://cognito-idp.<zone>.amazonaws.com/<client_id>/.well-known/jwks.json", "Namespace":"", "Audience":[<client_ID>, <application_ID>]}

```

```auto
{"errors":[{"message":"resolving updateGQLSchema failed because invalid jwt algorithm: found \"JWTURL\":\"https://cognito-idp.<zone>.amazonaws.com/<client_id>/.well-known/jwks.json\",, but supported options are: RS384,RS512,HS256,HS384,HS512,RS256 (Locations: [{Line: 3, Column: 4}])","extensions":{"code":"Error"}}]}

```

Is it something wrong with the binary parse? Like, the json not being well formated?

---

<div class="post-metadata">

**Author:** ![minhaj](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/minhaj/32/3468_2.png) [@minhaj](https://discuss.dgraph.io/u/minhaj)\
**Post date:** [June 8, 2021, 6:59pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474/8 "2021-06-08T18:59:35Z")

</div>

Remove ‘VerificationKey’ and make ‘JWTURL’ TO ‘JWKURL’.

---

<div class="post-metadata">

**Author:** ![Marco\_Antonio](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/marco_antonio/32/8361_2.png) [@Marco\_Antonio](https://discuss.dgraph.io/u/Marco_Antonio)\
**Post date:** [June 8, 2021, 7:11pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474/9 "2021-06-08T19:11:37Z")

</div>

Removing Algo and Verification key, and turning `JWTURL` to `JWKURL`, the error persists. Using:

```auto
# Dgraph.Authorization {"Header":"Authorization", "JWKURL":"https://cognito-idp.<zone>.amazonaws.com/<client_id>/.well-known/jwks.json", "Namespace":"", "Audience":[<client_ID>, <application_ID>]}

```

```auto
{"errors":[{"message":"resolving updateGQLSchema failed because invalid jwt algorithm: found \"JWKURL\":\"https://cognito-idp.sa-east-1.amazonaws.com/sa-east-1_xUd3VLsG3/.well-known/jwks.json\",, but supported options are: RS384,RS512,HS256,HS384,HS512,RS256 (Locations: [{Line: 3, Column: 4}])","extensions":{"code":"Error"}}]}

```

I’m triple checking to see if there’s some `"` or `'` misleading, but the sintax is `OK`.

---

<div class="post-metadata">

**Author:** ![Marco\_Antonio](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/marco_antonio/32/8361_2.png) [@Marco\_Antonio](https://discuss.dgraph.io/u/Marco_Antonio)\
**Post date:** [June 8, 2021, 7:34pm UTC](https://discuss.dgraph.io/t/auth-on-schema-invalid-alg/14474/10 "2021-06-08T19:34:33Z")

</div>

I think i’ve found the error. It was two:

First, I was using `JWTURL` when it should be `JWKURL`.  
Second, inside the Audience Key, inside the list, all its members must be inside `""`. Which, was not.

Since the visual studio graphql extension highlight treats everything as a comment after `#` (because it is), it does a terrible job a debbuging it.

Thanks for all the help and patience.
