> For the complete documentation index, see [llms.txt](https://docs.scaffold.ly/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scaffold.ly/how-tos/microservices/user-authentication.md).

# User Authentication

If you enabled the Authentication microservice, additional services are pre-wired to use it for pass-through authentication.

Within other microservices, use the `@Securty('jwt')` annotation in the Controller on methods to enforce that an `Authorization` header is required with the request.

![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2FMHshJTZ2sqGJ9rDBJJMa%2FScreen%20Shot%202021-10-20%20at%206.14.48%20PM.png?alt=media\&token=379dfe1b-2c99-44bf-acf8-7d1b5ae89f34)

### Testing Authentication Locally

Microservices running **Locally** are configured to allow authentication tokens from the **Nonlive** environment.

Go to the [Scaffoldly Dashboard](https://start.scaffold.ly/dashboard) and find the JWT Token Generator

![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2FF1gM81K0BH1oIxqQZQx5%2FScreen%20Shot%202021-10-20%20at%206.14.30%20PM.png?alt=media\&token=97490f2b-24c8-48d5-b380-3cc0c6c77d36)

By default, emails can only be sent to your Scaffoldly email account, also shown on the Dashboard

![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2FwFDTIGn71F5IJNNAOPRK%2FScreen%20Shot%202021-10-20%20at%204.59.14%20PM.png?alt=media\&token=e485a059-5de8-4132-af26-40e71ba0afed)

![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2F1LiJZxxmv2rLV5ZmA68P%2FScreen%20Shot%202021-10-20%20at%206.22.43%20PM.png?alt=media\&token=2cb77abe-7998-49ed-be43-580280a31ae5) ![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2FTZy63ZAQ6VZuRvrDmMP4%2FScreen%20Shot%202021-10-20%20at%206.24.14%20PM.png?alt=media\&token=b01665d5-8c3a-4438-87c7-cadef2b19d15) ![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2FNRogFBGeBadSEfbOWKpV%2FScreen%20Shot%202021-10-20%20at%206.24.55%20PM.png?alt=media\&token=bc41e8df-5d86-4bc1-a9d3-3f0b5d22149e) ![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2F6nAGyCavg0G729eDBcd8%2FScreen%20Shot%202021-10-20%20at%206.25.14%20PM.png?alt=media\&token=a4ea19db-1eb7-490f-9436-e327d918dac0)

Run your [Microservice locally](/how-tos/microservices/running-locally.md) (optionally in [Debug Mode](/how-tos/microservices/running-locally.md#debug-the-application)), and open the [Swagger UI](/how-tos/microservices/running-locally.md#use-the-application)

Click **Authorize** and paste the token, and invoke an endpoint with the padlock icon.

If you've set a breakpoint, you can see that the `httpRequest.user` is populated with the user's identity.

![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2FVWg8C494oRaj5L70Fhfp%2FScreen%20Shot%202021-10-20%20at%206.29.38%20PM.png?alt=media\&token=f9267e35-4baa-4e89-bc55-285ce61f3ee3) ![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2Fh0S7d7xh5RtsdqXIQwaq%2FScreen%20Shot%202021-10-20%20at%206.29.55%20PM.png?alt=media\&token=caf2333b-afee-4d76-bff1-cfde921ba92e) ![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2FdsP7yYctzWKo4Pm9mfiv%2FScreen%20Shot%202021-10-20%20at%206.31.30%20PM.png?alt=media\&token=eee62dc9-cdec-4872-94e3-97bece7e1c57) ![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2Fa48vkx7KayN8rKpNfMDj%2FScreen%20Shot%202021-10-20%20at%206.32.22%20PM.png?alt=media\&token=7635e921-2a5c-4aee-85de-501a7fac3531) ![](https://968799697-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MKLlfWGgG_lqg_w6lw2%2Fuploads%2FGwg5lNpIhv2kGUVZ3MRe%2FScreen%20Shot%202021-10-20%20at%206.33.00%20PM.png?alt=media\&token=958421b0-f321-481d-822f-0a08a2c1b2f4)
