# How to work with JWT and laminas api tools?

**URL:** <https://discourse.laminas.dev/t/how-to-work-with-jwt-and-laminas-api-tools/1760>\
**Category:** API Tools\
**Created:** [July 26, 2020, 11:48pm UTC](https://discourse.laminas.dev/t/how-to-work-with-jwt-and-laminas-api-tools/1760 "2020-07-26T23:48:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adarsh\_Khatri](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/adarsh_khatri/32/713_2.png) [@Adarsh\_Khatri](https://discourse.laminas.dev/u/Adarsh_Khatri)\
**Post date:** [July 26, 2020, 11:48pm UTC](https://discourse.laminas.dev/t/how-to-work-with-jwt-and-laminas-api-tools/1760/1 "2020-07-26T23:48:31Z")

</div>

I am new to Laminas API tools.  
I am working on a project where I am trying to achieve similar to google.

So basically I will have a separate database for my users which later can be used for different projects. And my API project will be calling a separate database.

While I can send JWT authentication from angular to API, I am not sure how should I be handling the JWT token?

What I want:

1. Send authentication (JWT) from angular to laminas API
2. Laminas API checks the authentication and authenticate
3. Laminas also checks if the user has permission to access the resources

I am mainly puzzled in number 3, how do I handle the permission in API? I can send a list of claims in JWT, but how would I validate that in API?

Any suggestions?

---

<div class="post-metadata">

**Author:** ![ocramius](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/ocramius/32/23_2.png) [@ocramius](https://discourse.laminas.dev/u/ocramius)\
**Post date:** [July 27, 2020, 7:53am UTC](https://discourse.laminas.dev/t/how-to-work-with-jwt-and-laminas-api-tools/1760/2 "2020-07-27T07:53:08Z")

</div>

> > > |
> > 
> > - | - |
> 
> I am mainly puzzled in number 3, how do I handle the permission in API? I can send a list of claims in JWT, but how would I validate that in API?

You can:

1. extract the token claims in a middleware, put them into the `ServerRequest` attributes
2. use the claim from the `ServerRequest` in a post-routing middleware, match them against routes and decide whether that matches your authorization model
