grpc/grpc-go · error

jwt_token_file is required in JWT call credentials config

Error message

jwt_token_file is required in JWT call credentials config

What it means

Returned by jwtcreds.NewCallCredentials when the config unmarshalled successfully but jwt_token_file is empty. The token file path is mandatory for JWT call credentials.

Solutions

  1. Provide a non-empty jwt_token_file path in the call_creds config.
  2. If JWT call creds are not needed, remove the call_creds entry or disable the call-creds feature flag.
  3. Ensure the bootstrap generator/template fills this field.

Example fix

// before
{"type":"jwt","config":{}}

// after
{"type":"jwt","config":{"jwt_token_file":"/var/secrets/token.jwt"}}
Defensive patterns

Strategy: validation

Validate before calling

// Ensure jwt_token_file is non-empty.
func requireJWTTokenFile(raw json.RawMessage) error {
    var cfg struct {
        JWTTokenFile string `json:"jwt_token_file"`
    }
    _ = json.Unmarshal(raw, &cfg)
    if cfg.JWTTokenFile == "" {
        return fmt.Errorf("jwt_token_file is required")
    }
    return nil
}

Try / catch

if _, _, err := jwtcreds.NewCallCredentials(cfg); err != nil {
    if strings.Contains(err.Error(), "jwt_token_file is required") {
        // set jwt_token_file before retrying.
    }
}

Prevention

When it happens

Trigger: Triggered at call_creds.go:47 when cfg.JWTTokenFile == "" after parsing. The field is either omitted or explicitly empty.

Common situations: jwt_token_file field omitted from the call_creds config; field present but empty; templating left the value blank.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/11064f96c280dc96. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/bootstrap/jwtcreds/call_creds.go:47

	"google.golang.org/grpc/credentials/jwt"
)

// NewCallCredentials returns a new JWT token based call credentials. The input
// config must match the structure specified in gRFC A97.
//
// The caller is expected to invoke the cancel function when they are done using
// the returned call creds. This cancel function is idempotent.
func NewCallCredentials(configJSON json.RawMessage) (c credentials.PerRPCCredentials, cancel func(), err error) {
	var cfg struct {
		JWTTokenFile string `json:"jwt_token_file"`
	}
	emptyFn := func() {}

	if err := json.Unmarshal(configJSON, &cfg); err != nil {
		return nil, emptyFn, fmt.Errorf("failed to unmarshal JWT call credentials config: %v", err)
	}
	if cfg.JWTTokenFile == "" {
		return nil, emptyFn, fmt.Errorf("jwt_token_file is required in JWT call credentials config")
	}
	callCreds, err := jwt.NewTokenFileCallCredentials(cfg.JWTTokenFile)
	if err != nil {
		return nil, emptyFn, fmt.Errorf("failed to create JWT call credentials: %v", err)
	}
	return callCreds, emptyFn, nil
}

View on GitHub (pinned to 0c51461d27)