Skip to content
pg_session_jwt

pg_session_jwt

pg_session_jwt : Manage authentication sessions using JWTs

Overview

IDExtensionPackageVersionCategoryLicenseLanguage
7060
pg_session_jwt
pg_session_jwt
0.5.0
SEC
Apache-2.0
Rust
AttributeHas BinaryHas LibraryNeed LoadHas DDLRelocatableTrusted
--s-dt-
No
Yes
No
Yes
no
yes
Relationships
Schemasauth
See Also
pgjwt
pgaudit
pgsodium
supabase_vault
anon

Packages

TypeRepoVersionPG Major CompatibilityPackage PatternDependencies
EXT
PIGSTY
0.5.0
18
17
16
15
14
pg_session_jwt-
RPM
PIGSTY
0.5.0
18
17
16
15
14
pg_session_jwt_$v-
DEB
PIGSTY
0.5.0
18
17
16
15
14
postgresql-$v-pg-session-jwt-
Linux / PGPG18PG17PG16PG15PG14
el8.x86_64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
el8.aarch64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
el9.x86_64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
el9.aarch64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
el10.x86_64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
el10.aarch64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
d12.x86_64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
d12.aarch64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
d13.x86_64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
d13.aarch64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
u22.x86_64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
u22.aarch64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
u24.x86_64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
u24.aarch64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
u26.x86_64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
u26.aarch64
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PIGSTY 0.5.0
PackageVersionOSORGSIZEFile URL
pg_session_jwt_180.5.0el8.x86_64pigsty1001.0 KiBpg_session_jwt_18-0.5.0-1PIGSTY.el8.x86_64.rpm
pg_session_jwt_180.5.0el8.aarch64pigsty923.1 KiBpg_session_jwt_18-0.5.0-1PIGSTY.el8.aarch64.rpm
pg_session_jwt_180.5.0el9.x86_64pigsty1014.1 KiBpg_session_jwt_18-0.5.0-1PIGSTY.el9.x86_64.rpm
pg_session_jwt_180.5.0el9.aarch64pigsty981.1 KiBpg_session_jwt_18-0.5.0-1PIGSTY.el9.aarch64.rpm
pg_session_jwt_180.5.0el10.x86_64pigsty1012.3 KiBpg_session_jwt_18-0.5.0-1PIGSTY.el10.x86_64.rpm
pg_session_jwt_180.5.0el10.aarch64pigsty960.0 KiBpg_session_jwt_18-0.5.0-1PIGSTY.el10.aarch64.rpm
postgresql-18-pg-session-jwt0.5.0d12.x86_64pigsty797.8 KiBpostgresql-18-pg-session-jwt_0.5.0-1PIGSTY~bookworm_amd64.deb
postgresql-18-pg-session-jwt0.5.0d12.aarch64pigsty684.5 KiBpostgresql-18-pg-session-jwt_0.5.0-1PIGSTY~bookworm_arm64.deb
postgresql-18-pg-session-jwt0.5.0d13.x86_64pigsty796.8 KiBpostgresql-18-pg-session-jwt_0.5.0-1PIGSTY~trixie_amd64.deb
postgresql-18-pg-session-jwt0.5.0d13.aarch64pigsty685.8 KiBpostgresql-18-pg-session-jwt_0.5.0-1PIGSTY~trixie_arm64.deb
postgresql-18-pg-session-jwt0.5.0u22.x86_64pigsty893.3 KiBpostgresql-18-pg-session-jwt_0.5.0-1PIGSTY~jammy_amd64.deb
postgresql-18-pg-session-jwt0.5.0u22.aarch64pigsty812.8 KiBpostgresql-18-pg-session-jwt_0.5.0-1PIGSTY~jammy_arm64.deb
postgresql-18-pg-session-jwt0.5.0u24.x86_64pigsty888.3 KiBpostgresql-18-pg-session-jwt_0.5.0-1PIGSTY~noble_amd64.deb
postgresql-18-pg-session-jwt0.5.0u24.aarch64pigsty802.6 KiBpostgresql-18-pg-session-jwt_0.5.0-1PIGSTY~noble_arm64.deb
postgresql-18-pg-session-jwt0.5.0u26.x86_64pigsty879.7 KiBpostgresql-18-pg-session-jwt_0.5.0-1PIGSTY~resolute_amd64.deb
postgresql-18-pg-session-jwt0.5.0u26.aarch64pigsty801.7 KiBpostgresql-18-pg-session-jwt_0.5.0-1PIGSTY~resolute_arm64.deb

Source

pig build pkg pg_session_jwt;		# build rpm/deb

Install

Make sure PGDG and PIGSTY repo available:

pig repo add pgsql -u   # add both repo and update cache

Install this extension with pig:

pig install pg_session_jwt;		# install via package name, for the active PG version

pig install pg_session_jwt -v 18;   # install for PG 18
pig install pg_session_jwt -v 17;   # install for PG 17
pig install pg_session_jwt -v 16;   # install for PG 16
pig install pg_session_jwt -v 15;   # install for PG 15
pig install pg_session_jwt -v 14;   # install for PG 14

Create this extension with:

CREATE EXTENSION pg_session_jwt;

Usage

Sources: README, v0.5.0 tag, control file

pg_session_jwt handles authenticated sessions through JWTs. When configured with a JWK, it verifies JWT authenticity. Without a JWK, it falls back to PostgREST-compatible request.jwt.claims.

CREATE EXTENSION pg_session_jwt;

Mode 1: JWK Validation

Set the JWK at connection time via libpq options:

export PGOPTIONS="-c pg_session_jwt.jwk=$MY_JWK"

Then within the session:

SELECT auth.init();                        -- Initialize with JWK
SELECT auth.jwt_session_init('eyJ...');    -- Set and validate the JWT
SELECT auth.user_id();                     -- Get the 'sub' claim
SELECT auth.session();                     -- Get full JWT payload as JSONB

Mode 2: PostgREST-Compatible (No JWK)

Works out of the box with PostgREST. No initialization needed:

SELECT auth.user_id();   -- Returns 'sub' from request.jwt.claims
SELECT auth.session();   -- Returns full claims as JSONB

Functions

FunctionReturnsDescription
auth.init()voidInitialize session using JWK
auth.jwt_session_init(jwt text)voidSet and validate a JWT
auth.session()jsonbGet JWT payload or fallback claims
auth.jwt()jsonbAlias for auth.session()
auth.user_id()textGet the sub claim
auth.uid()uuidGet sub as UUID (or NULL)
auth.organization()jsonbNeon Auth organization claim helper
auth.organization_id()uuidNeon Auth organization id helper

Configuration

ParameterDescription
pg_session_jwt.jwkJWK for JWT validation (set at startup or connection)
pg_session_jwt.audit_logEnable audit logging (on/off)

RLS Example

CREATE POLICY user_isolation ON my_table
    USING (user_id = auth.user_id());

For Neon Auth organization-scoped policies, use the o claim helpers:

CREATE POLICY team_select ON team
  FOR SELECT
  USING (organization_id = auth.organization_id());

Version Notes

The v0.5.0 README adds Neon Auth organization helpers and explicitly separates portable helpers such as auth.jwt(), auth.user_id(), and auth.uid() from Neon-specific auth.organization() and auth.organization_id(). Other auth providers should use auth.jwt() and extract provider-specific claims directly.

Last updated on