Spring Boot OAuth2 with encrypted JWT access token

In my Spring Bott application I have configured own OAuth2 with Authorization/Resource servers.

I have implemented following JwtAccessTokenConverter:

public JwtAccessTokenConverter accessTokenConverter() {
    JwtAccessTokenConverter converter = new JwtAccessTokenConverter() {

        public OAuth2AccessToken enhance(OAuth2AccessToken accessToken, OAuth2Authentication authentication) {
            DBUserDetails user = (DBUserDetails) authentication.getUserAuthentication().getPrincipal();
            final Map<String, Object> additionalInfo = new HashMap<>();
            additionalInfo.put("user_id", user.getUser().getId());
            ((DefaultOAuth2AccessToken) accessToken).setAdditionalInformation(additionalInfo);
            OAuth2AccessToken enhancedToken = super.enhance(accessToken, authentication);
            return enhancedToken;



    DefaultAccessTokenConverter accessTokenConverter = new DefaultAccessTokenConverter();
    DefaultUserAuthenticationConverter userTokenConverter = new DefaultUserAuthenticationConverter();


    return converter;

Right now my application produces following tokens, for example:


This token can be decoded with JWT debugger here https://jwt.io/

I don't want to expose the internals of this token to external world and would like to encode this token in a some way.

How it can be implemented with Spring Boot, OAuth2, JWT ?

1 Answers

i try this and it is working for me:https://gist.github.com/salgmachine/352799a6052b02901982dcbf85d30346

Create Custom JwtAccessTokenConverter

public class JwtJweAccessTokenConverter extends JwtAccessTokenConverter {

    RSAKey recipientJWK, recipientPublicJWK;

    public JwtJweAccessTokenConverter() {
        try {
            recipientJWK = new RSAKeyGenerator(2048).keyID("456").keyUse(KeyUse.ENCRYPTION).generate();
            recipientPublicJWK = recipientJWK.toPublicJWK();
        } catch (JOSEException e) {
            // TODO Auto-generated catch block

    protected String encode(OAuth2AccessToken accessToken, OAuth2Authentication authentication) {
        String jwt = super.encode(accessToken, authentication);

        try {
            // jwt is already signed at this point (by JwtAccessTokenConverter)
            SignedJWT parsed = SignedJWT.parse(jwt);

            // Create JWE object with signed JWT as payload
            JWEObject jweObject = new JWEObject(
                    new JWEHeader.Builder(JWEAlgorithm.RSA_OAEP_256, EncryptionMethod.A256GCM).contentType("JWT") // required
                                                                                                                    // to
                                                                                                                    // indicate
                                                                                                                    // nested
                                                                                                                    // JWT
                    new Payload(parsed));

            // Encrypt with the recipient's public key
            jweObject.encrypt(new RSAEncrypter(recipientPublicJWK));

            // Serialise to JWE compact form
            String jweString = jweObject.serialize();

            return jweString;
        } catch (Exception e) {

        return jwt;

    protected Map<String, Object> decode(String token) {
        try {
            // basically treat the incoming token as an encrypted JWT
            EncryptedJWT parse = EncryptedJWT.parse(token);
            // decrypt it
            RSADecrypter dec = new RSADecrypter(recipientJWK);
            // content of the encrypted token is a signed JWT (signed by
            // JwtAccessTokenConverter)
            SignedJWT signedJWT = parse.getPayload().toSignedJWT();
            // pass on the serialized, signed JWT to JwtAccessTokenConverter
            return super.decode(signedJWT.serialize());

        } catch (ParseException e) {
        } catch (JOSEException e) {

        return super.decode(token);

And Config your Oauth2 Auth server and resource to use your Custom JwtAccessTokenConverter

public TokenStore tokenStore() {

    return new JwtTokenStore(accessTokenConverter());

public JwtAccessTokenConverter accessTokenConverter() {
    final JwtAccessTokenConverter converter = new JwtJweAccessTokenConverter();
    final KeyStoreKeyFactory keyStoreKeyFactory = new KeyStoreKeyFactory(new ClassPathResource("mytest.jks"),
    return converter;

Check github link for completed code example

