My App
Tham chiếu

Trusted headers

Danh sách tham chiếu Gateway trusted headers.

Sau branch-token validation, Gateway inject:

  • X-Account-Id
  • X-Workspace-Id
  • X-Member-Id
  • X-Active-Branch-Id
  • X-Branch-Ids
  • X-Roles
  • X-Token-Scope=BRANCH
  • X-Request-Id
  • X-Correlation-Id

Downstream service nên dùng các header này và không tự verify client JWT trong runtime internal bình thường.