# Does the CLAIMS-KEY have to be a url?

**URL:** <https://discuss.dgraph.io/t/does-the-claims-key-have-to-be-a-url/7440>\
**Category:** GraphQL\
**Tags:** auth, docs\
**Created:** [June 30, 2020, 6:57pm UTC](https://discuss.dgraph.io/t/does-the-claims-key-have-to-be-a-url/7440 "2020-06-30T18:57:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![amaster507](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/amaster507/32/4123_2.png) [@amaster507](https://discuss.dgraph.io/u/amaster507)\
**Post date:** [June 30, 2020, 6:57pm UTC](https://discuss.dgraph.io/t/does-the-claims-key-have-to-be-a-url/7440/1 "2020-06-30T18:57:25Z")

</div>

From the docs: [https://graphql.dgraph.io/authorization/](https://graphql.dgraph.io/authorization/)

> `# Dgraph.Authorization HEADER CLAIMS-KEY ALGORITHM KEY`
> 
> - `CLAIMS-KEY` is the key inside the JWT that contains the claims relevant to Dgraph auth

> `# Dgraph.Authorization X-My-App-Auth https://my.app.io/jwt/claims HS256 "secretkey"`

> …expect[s] the JWT to contain custom claims object `"https://my.app.io/jwt/claims": { ... }` with the claims used in authorization rules.

The example given uses a URL (to a non-existent domain) for the `CLAIMS-KEY`.

Is there any reason why I should use a URL instead of my own custom variable name such as `data` or `variables`? Is there an alternative purpose of using a URL here? If I use my own domain name what if anything should be the endpoint of that URL?

---

<div class="post-metadata">

**Author:** ![pawan](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/pawan/32/1946_2.png) [@pawan](https://discuss.dgraph.io/u/pawan)\
**Post date:** [July 2, 2020, 1:06pm UTC](https://discuss.dgraph.io/t/does-the-claims-key-have-to-be-a-url/7440/2 "2020-07-02T13:06:14Z")

</div>

Hi @amaster507

The custom claims key can be anything. It doesn’t have to be a URL. We don’t check that it is a valid URL. It is usually used to have some distinction between claims belonging to different endpoints. Whatever is specified in the schema would be used to extract the variables.
