JWT rejected (401)
Symptom
- Agent Protocol or MCP returns 401.
- The Bearer token decodes (header and payload look fine).
- Unsigned requests are also rejected (expected).
Cause
The platform checks iss, aud, and the JWKS signature.
Common mismatches:
- Helm
platform.tenants.jwt.issueris not the tokeniss(for example an in-cluster Service URL while tokens still carry the public IdP URL). remoteJwksUriis an in-cluster HTTP URL that 404s without the publicHostheader.- NetworkPolicies are on and Aegra/MCP cannot reach HTTPS JWKS (missing
jwksEgressCIDRs).
Confirm
bash
# Token iss vs Helm issuer
helm get values zelkor-platform -n zelkor -o yaml | grep -A20 'jwt:'Decode the token payload (do not paste secrets into tickets). iss must equal platform.tenants.jwt.issuer. aud must include one of audiences.
bash
kubectl -n zelkor get networkpolicy -l app.kubernetes.io/instance=zelkor-platformWith NetworkPolicies on and remoteJwksUri set, the Aegra and MCP egress policies must include an ipBlock on TCP 443.
Fix
- Set
issuerto the publicissstring the IdP puts in tokens. - Prefer
--jwks-file/jwksConfigMapwhen the IdP JWKS is not reachable as HTTPS without a special Host. - For a public HTTPS JWKS with NetworkPolicies, set
platform.tenants.jwt.jwksEgressCIDRsto the IdP CIDRs and upgrade.