> ## Documentation Index
> Fetch the complete documentation index at: https://translations.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> Découvrez comment configurer les requêtes d’autorisation sécurisées par JWT (JAR) pour une application.

# Configurer les requêtes d’autorisation sécurisées par JWT (JAR)

export const AuthCodeBlock = ({filename, icon, language, highlight, children}) => {
  const [displayText, setDisplayText] = useState(children);
  const [copyText, setCopyText] = useState(children);
  const wrapperRef = React.useRef(null);
  useEffect(() => {
    let unsubscribe = null;
    function init() {
      if (!window.autorun || !window.rootStore) {
        return;
      }
      unsubscribe = window.autorun(() => {
        let processedChildrenForDisplay = children;
        let processedChildrenForCopy = children;
        for (const [key, value] of window.rootStore.variableStore.values.entries()) {
          const escapedKey = key.replaceAll(/[.*+?^${}()|[\]\\]/g, (String.raw)`\$&`);
          let displayValue = value;
          if (key === "{yourClientSecret}" && value !== "{yourClientSecret}") {
            displayValue = value.substring(0, 3) + "*****MASKED*****";
          }
          processedChildrenForDisplay = processedChildrenForDisplay.replaceAll(new RegExp(escapedKey, "g"), displayValue);
          processedChildrenForCopy = processedChildrenForCopy.replaceAll(new RegExp(escapedKey, "g"), value);
        }
        setDisplayText(processedChildrenForDisplay);
        setCopyText(processedChildrenForCopy);
      });
    }
    if (window.rootStore) {
      init();
    } else {
      window.addEventListener("adu:storeReady", init);
    }
    return () => {
      window.removeEventListener("adu:storeReady", init);
      unsubscribe?.();
    };
  }, [children]);
  useEffect(() => {
    if (!wrapperRef.current) return;
    const originalWriteText = navigator.clipboard.writeText.bind(navigator.clipboard);
    let isOverriding = false;
    const handleClick = e => {
      const button = e.target.closest('[data-testid="copy-code-button"]');
      if (!button || !wrapperRef.current.contains(button)) return;
      isOverriding = true;
      navigator.clipboard.writeText = text => {
        if (isOverriding) {
          isOverriding = false;
          navigator.clipboard.writeText = originalWriteText;
          return originalWriteText(copyText);
        }
        return originalWriteText(text);
      };
      setTimeout(() => {
        if (isOverriding) {
          isOverriding = false;
          navigator.clipboard.writeText = originalWriteText;
        }
      }, 100);
    };
    const wrapper = wrapperRef.current;
    wrapper.addEventListener('click', handleClick, true);
    return () => {
      wrapper.removeEventListener('click', handleClick, true);
      if (navigator.clipboard.writeText !== originalWriteText) {
        navigator.clipboard.writeText = originalWriteText;
      }
    };
  }, [copyText]);
  return <div ref={wrapperRef}>
      <CodeBlock filename={filename} icon={icon} language={language} lines highlight={highlight}>
        {displayText}
      </CodeBlock>
    </div>;
};

export const codeExample1 = `POST https://{yourTenant}.auth0.com/api/v2/clients/{yourClientId}/credentials
  Authorization: Bearer <YOUR_ACCESS_TOKEN>
  Content-Type: application/json
  {
    "name": "Mes informations d’identification pour JAR",
    "credential_type": "public_key",
    "pem": "[YOUR PEM FILE CONTENT]",
    "alg": "RS256"
  }`;

export const codeExample2 = `PATCH https://{yourTenant}.auth0.com/api/v2/clients/{yourClientId}
Authorization: Bearer <YOUR_ACCESS_TOKEN>
Content-Type: application/json
{
  "signed_request_object": {
    "credentials": [{"id": "[YOUR CREDENTIAL ID]"}]
  }
}`;

<Callout icon="file-lines" color="#0EA5E9" iconType="regular">
  Pour utiliser les fonctionnalités de Highly Regulated Identity, vous devez avoir un forfait Enterprise avec le module complémentaire Highly Regulated Identity. Consultez la [tarification d’Auth0](https://auth0.com/pricing/) pour en savoir plus.
</Callout>

<Tooltip tip="JSON Web Token (JWT) : format standard des jetons d’identification (et souvent des jetons d’accès) utilisé pour transmettre de façon sécurisée des assertions entre deux parties." cta="Voir le glossaire" href="/fr-CA/docs/glossary?term=JWT">JWT</Tooltip>-Secured Authorization Requests (JAR) permettent de regrouper les paramètres d’une demande d’autorisation OAuth2 dans un seul paramètre de requête JWT, qui est ensuite signé afin d’en garantir l’intégrité.

<div id="prerequisites">
  ## Prérequis
</div>

Avant de configurer votre application pour utiliser JAR, vous devez [générer une paire de clés RSA](/fr-CA/docs/secure/application-credentials/generate-rsa-key-pair).

<Warning>
  Vous devriez générer une paire de clés distincte pour chaque type d’utilisation des informations d’identification. Par exemple, ne réutilisez pas la même paire de clés à la fois pour JAR et pour l’authentification par clé privée JWT.
</Warning>

<div id="configure-jar-for-an-application">
  ## Configurer JAR pour une application
</div>

Vous pouvez configurer JAR pour une application à l’aide du <Tooltip tip="Auth0 Dashboard : le principal produit d’Auth0 pour configurer vos services." cta="Voir le glossaire" href="/fr-CA/docs/glossary?term=Auth0+Dashboard">tableau de bord Auth0</Tooltip> et de l’<Tooltip tip="Auth0 Dashboard : le principal produit d’Auth0 pour configurer vos services." cta="Voir le glossaire" href="/fr-CA/docs/glossary?term=Management+API">API de gestion</Tooltip>.

<Tabs>
  <Tab title="Tableau de bord Auth0">
    Utilisez le tableau de bord Auth0 pour configurer votre application afin qu’elle utilise JAR avec des clés RSA générées au préalable.

    1. Accédez à [tableau de bord Auth0 > Applications](https://manage.auth0.com/#/applications).
    2. Sélectionnez l’application que vous souhaitez utiliser avec JAR.
    3. Sélectionnez l’onglet **Application Settings**.
    4. Dans la section **Authorization Requests**, activez **Require JWT-Secured Authorization Requests**.
    5. Si aucune information d’identification n’est attribuée et que des informations d’identification sont disponibles, vous serez invité à attribuer une information d’identification existante.

           <Frame>
             <img src="https://mintcdn.com/translations/mMSz-RNYLuOm2GmQ/docs/images/cdy7uua7fh8z/HQHhFWTtdfNa5TnZ1dwx6/e47068cc9e85c538f80476162f4314a3/Existing_Creds_-_English.png?fit=max&auto=format&n=mMSz-RNYLuOm2GmQ&q=85&s=563a22423de44f705848d08249cd327c" alt="Tableau de bord > Application > Paramètres > Attribuer des informations d’identification existantes" data-og-width="792" width="792" data-og-height="688" height="688" data-path="docs/images/cdy7uua7fh8z/HQHhFWTtdfNa5TnZ1dwx6/e47068cc9e85c538f80476162f4314a3/Existing_Creds_-_English.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/translations/mMSz-RNYLuOm2GmQ/docs/images/cdy7uua7fh8z/HQHhFWTtdfNa5TnZ1dwx6/e47068cc9e85c538f80476162f4314a3/Existing_Creds_-_English.png?w=280&fit=max&auto=format&n=mMSz-RNYLuOm2GmQ&q=85&s=43bd8a48e25024ebc4e120dc583617bf 280w, https://mintcdn.com/translations/mMSz-RNYLuOm2GmQ/docs/images/cdy7uua7fh8z/HQHhFWTtdfNa5TnZ1dwx6/e47068cc9e85c538f80476162f4314a3/Existing_Creds_-_English.png?w=560&fit=max&auto=format&n=mMSz-RNYLuOm2GmQ&q=85&s=80d27bf6d7bded96c2ca9b145ea3d039 560w, https://mintcdn.com/translations/mMSz-RNYLuOm2GmQ/docs/images/cdy7uua7fh8z/HQHhFWTtdfNa5TnZ1dwx6/e47068cc9e85c538f80476162f4314a3/Existing_Creds_-_English.png?w=840&fit=max&auto=format&n=mMSz-RNYLuOm2GmQ&q=85&s=02bb47a10e6f61d023daf18f249985d0 840w, https://mintcdn.com/translations/mMSz-RNYLuOm2GmQ/docs/images/cdy7uua7fh8z/HQHhFWTtdfNa5TnZ1dwx6/e47068cc9e85c538f80476162f4314a3/Existing_Creds_-_English.png?w=1100&fit=max&auto=format&n=mMSz-RNYLuOm2GmQ&q=85&s=caf70b98741e84fc03b0b97da058ce7b 1100w, https://mintcdn.com/translations/mMSz-RNYLuOm2GmQ/docs/images/cdy7uua7fh8z/HQHhFWTtdfNa5TnZ1dwx6/e47068cc9e85c538f80476162f4314a3/Existing_Creds_-_English.png?w=1650&fit=max&auto=format&n=mMSz-RNYLuOm2GmQ&q=85&s=c924bf2bb2cadfbeb6d9ed56c855b9f3 1650w, https://mintcdn.com/translations/mMSz-RNYLuOm2GmQ/docs/images/cdy7uua7fh8z/HQHhFWTtdfNa5TnZ1dwx6/e47068cc9e85c538f80476162f4314a3/Existing_Creds_-_English.png?w=2500&fit=max&auto=format&n=mMSz-RNYLuOm2GmQ&q=85&s=2be02e7ff6ac45e2f50c3bb0aa976fe8 2500w" />
           </Frame>
    6. Vous aurez aussi la possibilité d’attribuer une nouvelle information d’identification.

           <Frame>
             <img src="https://mintcdn.com/translations/c0RQ9V0YAcT0-8l5/docs/images/cdy7uua7fh8z/7JfsCBwytWO6Q7hUvdtSwJ/b85fd39fea7330a31496f51347767ae7/New_Creds_-_EN.png?fit=max&auto=format&n=c0RQ9V0YAcT0-8l5&q=85&s=aefb9bfd7421e2509f95f3bd8a334078" alt="Tableau de bord Auth0 > Applications > Paramètres > Attribuer de nouvelles informations d’identification" data-og-width="702" width="702" data-og-height="366" height="366" data-path="docs/images/cdy7uua7fh8z/7JfsCBwytWO6Q7hUvdtSwJ/b85fd39fea7330a31496f51347767ae7/New_Creds_-_EN.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/translations/c0RQ9V0YAcT0-8l5/docs/images/cdy7uua7fh8z/7JfsCBwytWO6Q7hUvdtSwJ/b85fd39fea7330a31496f51347767ae7/New_Creds_-_EN.png?w=280&fit=max&auto=format&n=c0RQ9V0YAcT0-8l5&q=85&s=840b171f616c5ffa3e6a5516c4a8b582 280w, https://mintcdn.com/translations/c0RQ9V0YAcT0-8l5/docs/images/cdy7uua7fh8z/7JfsCBwytWO6Q7hUvdtSwJ/b85fd39fea7330a31496f51347767ae7/New_Creds_-_EN.png?w=560&fit=max&auto=format&n=c0RQ9V0YAcT0-8l5&q=85&s=f399f3a4a327b5e268ae8dc0665ac273 560w, https://mintcdn.com/translations/c0RQ9V0YAcT0-8l5/docs/images/cdy7uua7fh8z/7JfsCBwytWO6Q7hUvdtSwJ/b85fd39fea7330a31496f51347767ae7/New_Creds_-_EN.png?w=840&fit=max&auto=format&n=c0RQ9V0YAcT0-8l5&q=85&s=77c086b91ce428508aebd23d042e8d9a 840w, https://mintcdn.com/translations/c0RQ9V0YAcT0-8l5/docs/images/cdy7uua7fh8z/7JfsCBwytWO6Q7hUvdtSwJ/b85fd39fea7330a31496f51347767ae7/New_Creds_-_EN.png?w=1100&fit=max&auto=format&n=c0RQ9V0YAcT0-8l5&q=85&s=aca496b345ddb1e254cb2621bf520627 1100w, https://mintcdn.com/translations/c0RQ9V0YAcT0-8l5/docs/images/cdy7uua7fh8z/7JfsCBwytWO6Q7hUvdtSwJ/b85fd39fea7330a31496f51347767ae7/New_Creds_-_EN.png?w=1650&fit=max&auto=format&n=c0RQ9V0YAcT0-8l5&q=85&s=0a2ac8150e19326e2789fbde8ae1b075 1650w, https://mintcdn.com/translations/c0RQ9V0YAcT0-8l5/docs/images/cdy7uua7fh8z/7JfsCBwytWO6Q7hUvdtSwJ/b85fd39fea7330a31496f51347767ae7/New_Creds_-_EN.png?w=2500&fit=max&auto=format&n=c0RQ9V0YAcT0-8l5&q=85&s=20347b474ba2c2db11fbf53fb5115937 2500w" />
           </Frame>
    7. Ajoutez et attribuez une nouvelle information d’identification en téléversant une paire de clés RSA générée au préalable. Lorsque vous y êtes invité, saisissez ce qui suit :

       * **Name** : un nom pour identifier l’information d’identification
       * **Public Key** : la clé publique du certificat X.509 au format PEM
       * **Algorithm** : sélectionnez l’algorithme de signature JAR
       * **Expiration Date** : définissez la date d’expiration de l’information d’identification
  </Tab>

  <Tab title="API de gestion">
    Utilisez l’[API de gestion](https://auth0.com/docs/api/management/v2) pour configurer JAR pour votre application à l’aide de la propriété de configuration client `signed_request_object`. Cette propriété d’objet contient les champs suivants :

    * `required` : oblige toutes les demandes d’autorisation vers `/authorize` et `/oauth/par` à utiliser JAR. Pour en savoir plus, consultez [flux de code d’autorisation avec des requêtes d’autorisation sécurisées par JWT](/fr-CA/docs/get-started/authentication-and-authorization-flow/authorization-code-flow/authorization-code-flow-with-jar).
    * `credentials` : un tableau d’ID d’informations d’identification utilisés pour vérifier les signatures.

    <Callout icon="file-lines" color="#0EA5E9" iconType="regular">
      Le paramètre credentials se comporte de façon similaire au paramètre Private Key JWT `client_authentication_methods.private_key_jwt.credentials`, qui prend en charge la création d’informations d’identification lorsque vous créez une nouvelle application. Pour en savoir plus, consultez [Configure Private Key JWT](/fr-CA/docs/get-started/applications/configure-private-key-jwt).
    </Callout>

    Vous pouvez configurer JAR pour une nouvelle application ou une application existante au moyen de l’API de gestion.

    #### Configurer JAR pour une nouvelle application

    Lorsque vous créez une nouvelle application, configurez JAR en envoyant une requête POST avec `signed_request_object`. Dans cette requête POST, vous pouvez aussi enregistrer l’information d’identification client correspondante (c.-à-d. la clé PEM) :

    ```json lines theme={null}
    POST https://{yourTenant}.auth0.com/api/v2/clients
    Authorization: Bearer <YOUR_ACCESS_TOKEN>
    Content-Type: application/json
    {
      "name": "My App using JAR",
      "signed_request_object": {
          "required": true,
    "credentials": [{
            "name": "My credential for JAR",
            "credential_type": "public_key",
            "pem": "[YOUR PEM FILE CONTENT]",
            "alg": "RS256"
    }]
      },
      "jwt_configuration": {
        "alg": "RS256"
      }
    }
    ```

    #### Configurer JAR pour une application existante

    Lors de la mise à jour d’une application existante, vous devez d’abord créer explicitement une information d’identification client. La requête POST suivante utilise le contenu de votre fichier PEM pour créer vos informations d’identification client pour JAR :

    <AuthCodeBlock children={codeExample1} language="json" />

    <Callout icon="file-lines" color="#0EA5E9" iconType="regular">
      Assurez-vous que les sauts de ligne sont correctement encodés en JSON, sans mise en forme supplémentaire.
    </Callout>

    Ensuite, attribuez l’information d’identification client à la configuration client `signed_request_object`. La requête PATCH suivante associe vos informations d’identification client à `signed_request_object` :

    <AuthCodeBlock children={codeExample2} language="json" />
  </Tab>
</Tabs>

<div id="learn-more">
  ## En savoir plus
</div>

* [Flux de code d’autorisation avec des requêtes d’autorisation sécurisées par JWT (JAR)](/fr-CA/docs/get-started/authentication-and-authorization-flow/authorization-code-flow/authorization-code-flow-with-jar)
