core/crm-core/docs/security.md
2025-12-27 14:32:00 -03:00

286 B

Security

  • JWT required for all routes except /health.
  • JWKS validation used for token verification.
  • Required claims: sub (user ID), tenantId, roles.
  • Authorization scopes: crm.read, crm.write, crm.admin.
  • Tenant isolation enforced on every query via tenant_id.