core/crm-core/docs/security.md
2025-12-27 14:32:00 -03:00

7 lines
286 B
Markdown

# Security
- JWT required for all routes except `/health`.
- JWKS validation used for token verification.
- Required claims: `sub` (user ID), `tenantId`, `roles`.
- Authorization scopes: `crm.read`, `crm.write`, `crm.admin`.
- Tenant isolation enforced on every query via `tenant_id`.