HTTP > Make a JWT request module
The Adobe Workfront Fusion HTTP > Make a JWT request module sends an HTTP(S) request to a URL and authorizes it with a JSON Web Token (JWT) that the module signs for you on every call. The response is then processed the same way as in the standard HTTP > Make a request module.
This module behaves like the standard Make a request module, with one main difference: it automatically signs a JWT from the claims you provide and adds it to the request, by default as Authorization: Bearer <token>.
Use this module to call any API that expects a signed JWT for authentication, such as services that require a short-lived bearer token signed with a shared secret (HMAC) or a private key (RSA/ECDSA), without creating the token in a separate step.
If the API uses OAuth 2.0, Basic authentication, an API key, or a client certificate, use the matching dedicated HTTP module instead.
Access requirements
| table 0-row-2 1-row-2 2-row-2 3-row-2 layout-auto html-authored no-header | |
|---|---|
| Adobe Workfront package |
Any Adobe Workfront Workflow package and any Adobe Workfront Automation and Integration package Workfront Ultimate Workfront Prime and Select packages, with an additional purchase of Workfront Fusion. |
| Adobe Workfront licenses |
Standard Work or higher |
| Adobe Workfront Fusion license |
Operation-based: Available to organizations with operation-based licenses Connector-based (legacy): Workfront Fusion for Work Automation and Integration |
| Product | If your organization has a Select or Prime Workfront package that does not include Workfront Automation and Integration, your organization must purchase Adobe Workfront Fusion. |
For more detail about the information in this table, see Access requirements in documentation.
For information on Adobe Workfront Fusion licenses, see Adobe Workfront Fusion licenses.
Create a JWT connection
The module requires a JWT connection. The connection stores the signing material so the secret or private key does not have to appear in the scenario.
Create a JWT connection in Fusion
-
Add the HTTP > Make a JWT request module to your scenario.
-
Click Add next to the Connection field.
-
Configure the connection fields:
table 0-row-2 1-row-2 2-row-2 layout-auto html-authored no-header Connection name Enter a name for the connection. Algorithm Select the signing algorithm for the connection.
HS256HS384HS512RS256RS384RS512PS256PS384PS512ES256ES384ES512
Secret Enter the signing key.
- For
HS*algorithms, use the shared secret string. - For
RS*,PS*, andES*algorithms, use the PEM-encoded private key.
-
Click Continue to create the connection and return to the module.
HTTP > Make a JWT request module and its fields
When you configure the HTTP > Make a JWT request module, Adobe Workfront Fusion displays the fields listed below in the same order they appear in the module UI. A bolded title in a module indicates a required field. Fields marked as advanced are hidden unless you select Show advanced settings.
How the token is built
- The module collects the claims in the JWT Payload (Claims) field.
- Reserved claims such as
exp,iat, andnbfare converted to NumericDate values. - The module applies the Sign Options and signs the token using the algorithm from the connection.
- The signed token is placed in the request header defined by Header Name.
- If Token Type is set, the module adds the prefix before the token. For example,
Bearer eyJ…. - The request is sent, and the response is processed the same way as the standard HTTP > Make a request module.
The signed token is automatically masked in debug and error logs so it is never exposed.
Example
Connection
- Algorithm:
HS256 - Secret:
my-shared-secret
Module settings
-
URL:
https://api.example.com/v1/orders -
Method:
GET -
JWT Payload (Claims):
sub=service-account-42iss=make-integration
-
Sign Options:
expiresIn=1h
-
Header Name:
Authorization -
Token Type:
Bearer
Result
The module sends the request with a header similar to:
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
FAQ / gotchas
Why did my token expire so quickly?
You likely entered a bare number for expiresIn such as 3600. The jsonwebtoken library interprets plain numbers as milliseconds. Use a unit string such as "1h" or "3600s" instead.
When is the token created?
The module signs a fresh JWT each time the module runs, not when you create the connection. The connection stores only the signing material and algorithm, so claims such as iat and exp reflect the moment of that module run.
If the request retries within the same module execution, Fusion reuses the same signed token for those retry attempts instead of signing a new token for each attempt. Because of this, a very short expiresIn value can expire before a retry occurs and cause a retry to send an already-expired token. To avoid this, use a clear unit string such as "1h" or "3600s" and avoid overly short token lifetimes.
Can I change the algorithm per request?
No. The algorithm is fixed by the connection. If you need a different algorithm, create a different JWT connection.
Can I send the token in a custom header?
Yes. Set the Header Name field to a custom name, but it cannot contain a dot (.).
Can I send the raw token without Bearer?
Yes. Leave Token Type empty.
Is the token visible in logs?
No. The signed token is masked automatically in debug and error logs.
jsonwebtoken library and mirrors the standalone JWT app’s signing behavior, so the same inputs produce the same token as the standalone JWT app.