Skip to navigation

Set up JWT

Self-managed authentication integrated with your login system
View as Markdown
Enterprise feature

This feature is available only for the Enterprise plan. To get started, reach out to support@buildwithfern.com.

With JWT, you manage the entire auth flow. This involves building and signing a fern_token cookie that integrates your docs with your existing login system. Like OAuth, JWT enables:

How it works

  1. A user clicks Login on your docs site and is redirected to your authentication page.
  2. After authentication, your system signs a JWT with a secret key from Fern and sets it as a fern_token cookie.
  3. Fern reads the token to determine the user’s access and credentials.
alt [User has required role] [User lacks required role] alt [Cookie exists] [No cookie] Visit restricted page Check fern_token cookie Decode JWT with secret key Extract roles from JWT Check if user has required role Show restricted content User is shown a 404 page Redirect to login page Authenticate user Generate JWT with roles Set fern_token cookie Validate JWT and roles Show restricted content User logs in User Fern Docs Redirect URL Auth System

Configuration

1

Get your secret key

Reach out to Fern to get your secret key and send them the URL of your authentication page. This is where users are redirected after clicking Login.

2

Build the fern claim

The JWT payload must include a fern claim. What you include in the token’s fern claim controls which features are enabled: login only, RBAC, or API key injection.

{
"fern": {}
}
4

Enable RBAC or API key injection (optional)

Once your fern_token is working, configure the features you need:

  • Role-based access control — define roles in docs.yml and restrict navigation items or page content by role.
  • API key injection — configure the playground payload, including custom headers, multiple API keys, and per-environment credentials.