docs(mcp): name both verifying key settings

This commit is contained in:
pedrooot committed 2026-10-08 00:34:15 +02:00
1 parent 2f97402f43
commit 0edc786207
2 files changed
+4 -3

No files matched your search

+1 -1
View File
@@ -105,7 +105,7 @@ Deploy your own remote MCP server:
- Full control over deployment
- Requires Python 3.12+ or Docker
- Set `DJANGO_TOKEN_VERIFYING_KEY` to the Prowler API's JWT public key (PEM, `\n`-escaped newlines allowed) so the server verifies the signature of user tokens before forwarding them; without it only their expiration is checked
- Set `DJANGO_TOKEN_VERIFYING_KEY` to the Prowler API's JWT public key (PEM, `\n`-escaped newlines allowed), or `DJANGO_TOKEN_VERIFYING_KEY_FILE` to a file holding it, so the server verifies the signature of user tokens before forwarding them; with neither set only their expiration is checked
See the [Installation Guide](https://docs.prowler.com/getting-started/installation/prowler-mcp) for complete instructions.
@@ -57,8 +57,9 @@ class ProwlerAppAuth:
raise ValueError("Prowler API key format is incorrect")
elif mode == "http" and not self.jwt_verifying_key:
logger.warning(
"DJANGO_TOKEN_VERIFYING_KEY is not set: JWT signatures will not be "
"verified by the MCP server, only their expiration"
f"Neither DJANGO_TOKEN_VERIFYING_KEY nor {VERIFYING_KEY_FILE_ENV} is "
"set: JWT signatures will not be verified by the MCP server, only "
"their expiration"
)
def _parse_jwt(self, token: str) -> dict | None: