Skip to content

Commit e5c159e

Browse files
committed
docs: clarify anonymous token audience requirement in EXAMPLES.md
1 parent d368de7 commit e5c159e

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎EXAMPLES.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -278,7 +278,7 @@ async def verify_dpop_token(access_token, dpop_proof, http_method, http_url):
278278

279279
Anonymous Sessions give a visitor an Auth0 identity before they log in. The access token issued for an anonymous session is a standard Auth0 Bearer JWT, so this SDK validates it like any other token. The one difference is the `sub` claim, which starts with `anon@`.
280280

281-
An anonymous token passes verification by default. To treat anonymous callers differently, or block them, check the `sub` claim after verifying the token. The SDK does not make that authorization decision for you.
281+
An anonymous token is verified like any other. It must be issued for this API's audience. To treat anonymous callers differently, or block them, check the `sub` claim after verifying the token. The SDK does not make that authorization decision for you.
282282

283283
### Serve everyone, branch in the handler
284284

0 commit comments

Comments
 (0)