Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Authenticate the user in your application, then have your backend issue a signed JWT that the embedded editor can send to its service. Keep the signing key on the backend, authorize each token request, and follow the specific editor vendor’s claims, algorithm, and refresh requirements: there is no universal JWT profile for embedded editors.

How the authentication flow works

A JWT is a signed container of claims. Its contents are readable by whoever receives it, so it is not a place for passwords, API secrets, or other confidential data. The signature lets a service verify that a trusted issuer created the token and that its contents have not changed.

  1. Authenticate the user. The host application verifies the user through its normal sign-in flow.
  2. Authorize the requested feature. The application checks whether that user may use the relevant editor service or capability.
  3. Fetch a token from your backend. The editor’s configured provider calls an endpoint protected by the application’s existing session or another verified identity mechanism.
  4. Issue a vendor-specific JWT. The backend creates the claims required by the particular integration and signs the token with the deployment’s supported algorithm and key.
  5. Send the JWT to the vendor service. The editor integration passes it in the format that service expects, such as a callback result or an Authorization bearer header.

The browser may request a token, but it must not hold the signing secret or private key. A public token-minting endpoint that accepts arbitrary requests defeats the identity check: an attacker could ask your server to mint credentials without proving who they are. See CKEditor’s token endpoint guidance and TinyMCE AI’s JWT authentication guide.

JWT requirements depend on the editor and deployment

Do not copy claim names, permissions, or signing algorithms from one editor integration to another. The vendor’s current documentation for the specific service and deployment is authoritative.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Elebase USB to USB C Adapter for iPhone 18 Pro Max,USBC Car Charger Adapter
  • Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
  • Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
  • Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
  • Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
  • 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Integration Documented token details Implementation implication
CKEditor Cloud Services Claims include aud, iat, and sub. It supports HS256, HS384, and HS512 for Cloud Services tokens. An optional exp can shorten validity, and tokens no older than 24 hours are accepted. Use the environment ID as the audience; protect the access key; include only relevant roles or permissions. The 24-hour maximum is specific to this documented service.
CKEditor Converters APIs The JWT is sent as a bearer token in the Authorization header. Token generation should happen on the backend to keep the access key private. This describes the converters API authentication path; do not assume other Cloud Services requests use the same mechanism.
TinyMCE AI hosted cloud The documented profile includes aud, sub, iat, and exp. It uses an asymmetric key setup with RS-family or PS-family options; RS256 is recommended. Configure the matching public key with the vendor and keep the private key on your backend. Use the provider response format TinyMCE documents.
TinyMCE AI on-premises The on-premises AI guide specifies HS256. Confirm whether the service is hosted or on-premises before choosing an algorithm; the requirements differ.

For the CKEditor-specific claim meanings and algorithm options, use the Cloud Services token endpoint guide. For the Converters API bearer-token path, see CKEditor’s converter authentication documentation. TinyMCE documents hosted AI token claims and callbacks in its hosted AI JWT guide, and the separate on-premises requirement in its on-premises AI JWT guidance.

Build a protected token endpoint

The exact implementation depends on your framework and vendor’s JWT profile, but the endpoint should follow the same security boundaries:

  1. Require the user’s authenticated application session or equivalent verified identity.
  2. Check authorization for the editor feature before minting a token. Do not trust a user ID, role, or permission sent only by the browser.
  3. Build only the claims the vendor requires. Use the required audience and subject, correct timestamp units, and a suitably short expiration where the profile allows or requires it.
  4. Sign on the server with the documented algorithm and server-side key. For asymmetric signing, configure the corresponding public key with the vendor; never return the private key to the browser.
  5. Return the response shape the editor expects, over HTTPS, and avoid logging tokens or signing material.

For example, a provider callback might request an application endpoint and return the token to the editor. The pseudocode below illustrates the boundary, not a universal vendor response contract:

Rank #2
Anker USB-C Hub, 5-in-1 USB Hub for Laptops, 4K HDMI Multiport Adapter
  • 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
  • 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
  • Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
  • 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
  • What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
async function getEditorToken() {
  const response = await fetch('/api/editor-token', {
    credentials: 'same-origin',
    headers: { 'Accept': 'application/json' }
  });

  if (!response.ok) {
    throw new Error(`Editor token request failed: ${response.status}`);
  }

  const body = await response.json();
  return body.token;
}

Your backend route at /api/editor-token must verify the user session, authorize the feature, construct the correct JWT for the chosen integration, and return the property shape the editor expects. This is deliberately not a full signing example: selecting claims and algorithms without knowing the editor, deployment, and key configuration would be unsafe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connect the token provider to editor startup

Configure the editor integration to call your endpoint using the vendor’s documented callback name and return format. TinyMCE AI uses tinymceai_token_provider; its hosted AI integration obtains a token at initialization and requests refreshes periodically, typically every hour. The editor cannot become ready until it receives the initial token, so a token endpoint failure is an editor startup failure, not merely a later background issue. Follow the exact setup and response contract in the TinyMCE AI JWT guide.

Other integrations may fetch tokens differently. For CKEditor Converters APIs, the JWT is supplied in an Authorization bearer header; that path should not be mistaken for a universal editor configuration rule. Check the specific plugin or service guide, and verify whether it obtains tokens itself, expects an application callback, or requires your code to attach the header.

Rank #3
Sale
Anker USB C Hub, 7in1 Multi-Port USB Adapter, 4K@60Hz USBC to HDMI Splitter
  • Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
  • Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
  • Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
  • Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
  • What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.

Choose claims, expiry, and permissions deliberately

Audience and subject

The audience (aud) identifies the intended service environment where the vendor’s profile uses it. The subject (sub) identifies the user. A stable, non-secret application identifier is generally more useful than exposing unnecessary personal data, but the vendor’s accepted format takes precedence.

Issued-at and expiration

The issued-at (iat) claim records when the token was created. Expiration (exp) limits how long a token may be used when required or supported. These are timestamps with precise formatting requirements; confirm the units expected by your JWT library and service. Keep application and server clocks synchronized. CKEditor documents a 24-hour maximum token age for Cloud Services and permits exp to shorten the lifetime. TinyMCE hosted AI requires exp in its documented profile.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Roles and permissions

Include only the roles or permissions necessary for the features the user is authorized to access. CKEditor documents an auth roles/permissions claim where relevant, while TinyMCE AI uses permission claims for feature access. A valid signature does not make an over-privileged token safe: the backend must decide what the user may do before issuing it.

Rank #4
Sale
UGREEN USB to USB C Adapter Combo 4-Pack, 10Gbps USB C Converter Space Gray
  • Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
  • Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
  • Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
  • Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
  • Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft

Secure keys and the authorization boundary

  • Keep signing keys server-side. A CKEditor access key or TinyMCE private key exposed in frontend code can be used to forge tokens.
  • Authenticate every token request. Tie the endpoint to the host application’s verified identity, and apply the same authorization checks as the feature itself.
  • Do not treat UI controls as access control. Hiding a toolbar button or disabling a browser-side feature does not prevent a user from manipulating client requests. TinyMCE’s security guide warns that client-side applications can be bypassed and recommends HSTS for sites served over HTTPS.
  • Use the vendor’s exact profile. The TinyMCE hosted-cloud and on-premises AI deployments document different signing algorithms. A token signed with the wrong algorithm or key will be rejected.
  • Avoid unnecessary token exposure. Do not put tokens in URLs, client-visible logs, analytics, or error reports. Return them only to the authenticated client that needs them.

Test the complete integration

Test more than whether your JWT library can create a token. Exercise the application endpoint and an actual request to the vendor service in the target environment.

  • Signed-in users with and without permission: only authorized users should receive a token.
  • Unauthenticated requests: the endpoint should reject them rather than minting a token.
  • Missing, malformed, or incorrect claims: confirm the vendor rejects the token and your logs identify the configuration issue without exposing secrets.
  • Expired tokens and refresh: verify renewal occurs at the expected interval and that a rejected token can be recovered from cleanly.
  • Clock drift: check system time and timestamp units if a token appears valid locally but is rejected remotely.
  • Startup failure: verify the user sees a useful error if the first token request fails; this is especially important for TinyMCE AI because editor readiness depends on that initial response.
  • Permission changes: ensure a user who loses access cannot continue obtaining newly authorized tokens.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting JWT authentication

Symptom Likely cause What to check
Signature rejected Wrong signing algorithm, incorrect key, or a key that does not match the vendor’s configured public key. Confirm hosted versus on-premises deployment, algorithm name, key pairing, and vendor configuration.
Token rejected despite a valid signature Missing or incorrect audience, subject, issued-at, expiration, or permission claims. Compare the decoded claims with the exact service profile; a readable JWT payload is not encrypted, so do not share it publicly.
Token is rejected as too old or not yet valid Clock skew, incorrect timestamp units, or an issuance time outside the service’s allowed age. Synchronize clocks and confirm the JWT library’s timestamp conventions. CKEditor specifically notes system-time problems can affect tokens.
Editor does not finish initializing The first provider call failed, returned the wrong response shape, or was blocked by session/CORS configuration. Inspect the token request status, response body shape, browser network panel, and backend authorization logs. For TinyMCE AI, initial token retrieval is required before readiness.
Refresh works initially but later fails Expired session, stale authorization, or a provider callback that does not renew tokens as expected. Test renewal with a live session and confirm the callback obtains a fresh server-issued token instead of reusing an expired one.
Anyone can retrieve a token The token endpoint is public or trusts client-supplied identity and permissions. Require verified application authentication and enforce authorization on the backend before signing.

Performance, reliability, and cost considerations

A token request is part of editor initialization for integrations that fetch a token on startup. Keep the endpoint responsive and dependable, since a slow or unavailable service can delay readiness. TinyMCE AI’s hosted flow also refreshes periodically, typically hourly, so the endpoint needs to support repeat requests rather than treating issuance as a one-time setup action.

JWT authentication does not itself establish the cost of the editor service, the number of requests allowed, or the reliability of a vendor endpoint. Those details depend on the vendor plan and deployment and should be checked separately. Operationally, monitor token endpoint status and rejected-token responses, but redact tokens and keys from logs.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Anker USB C Hub, 5-in-1 USBC to HDMI Splitter with 4K Display
  • 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
  • Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
  • Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
  • HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
  • What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.

Or skip the browser setup

JWTs are useful when your application needs to authorize an embedded editor service. For website screenshots, a separate API can handle the browser capture without requiring you to run and maintain your own screenshot browser. ScreenshotNeo is a website screenshot API and MCP server from Yorker Media; it is not an editor-authentication provider.

One GET request can return a screenshot image or PDF. For example, this cURL command requests a WebP screenshot:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for supported parameters and response details. Cookie banners are accepted and removed before capture, along with supported newsletter popups and chat widgets; those steps can be disabled. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, with the response identifying the page verdict and billing status in headers. Its MCP server provides screenshot and PDF tools for AI agents, and the Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots.

Sign up free for ScreenshotNeo: 1,000 screenshots a month, no card required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Is a JWT encrypted?

No. A normal signed JWT’s claims can be read by its recipient; its signature provides integrity, not secrecy. Do not put credentials or signing keys in its payload.

Can the embedded editor sign its own JWT?

No. The signing key must stay on a trusted backend. The browser can request a token after the user is authenticated, but should never possess the key used to mint it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.