#378·jwt

Only some registered claims can be optionally required

Author: WalkerGriggsCreated Feb 7, 2024Updated Jun 12, 2025

I noticed that only a subset of the registered claims can be configured to be required.

PR #351, for example, adds the requireExp field to the core Validator.

Other fields like iat are hard-coded to not be required.

https://github.com/golang-jwt/jwt/blob/6bcdd9d5b6ecb03a80ac123d1a9dc363441cbffe/validator.go#L117-L119

We also have a 'expected' claims like expectedIss which are hard-coded to be required.

https://github.com/golang-jwt/jwt/blob/6bcdd9d5b6ecb03a80ac123d1a9dc363441cbffe/validator.go#L130-L134

Semantically, I find the line between "expected" and "required" to be extremely thin. I propose moving to a system like expiratedAt where no required field is hard-coded and all can be configured with ParserOptions

https://github.com/golang-jwt/jwt/blob/6bcdd9d5b6ecb03a80ac123d1a9dc363441cbffe/validator.go#L102-L107

This change would standardize on a two boolean system for each registered claims:

  • WithFoo which determines which claims should be verified if provided. For example, see WithIssuedAt and WithIssuedAt
  • WithFooRequired which determines which claims should be required. For example, see WithExpirationRequired

The existing API (from what I can see) will remain the same. This change would only add ParserOption funcs to fill in the missing gaps.

I'd be happy to work on a PR. Is this a welcome change? Does anyone have any feedback?