web: security: enabled: true authorized-endpoints: [ api ] allowed-endpoints: [ public ] idp: api-key: enabled: false resource: token-type: JWT #| opaque jwt: claims: [ role, x-role ] issuer-uri: ${IDP_ISSUER_URI} validIssuer: ${IDP_ISSUER_URI}