grpc/grpc-go · error
jwt_token_file is required in JWT call credentials config
Error message
jwt_token_file is required in JWT call credentials config
What it means
Returned by jwtcreds.NewCallCredentials when the config unmarshalled successfully but jwt_token_file is empty. The token file path is mandatory for JWT call credentials.
Solutions
- Provide a non-empty jwt_token_file path in the call_creds config.
- If JWT call creds are not needed, remove the call_creds entry or disable the call-creds feature flag.
- Ensure the bootstrap generator/template fills this field.
Example fix
// before
{"type":"jwt","config":{}}
// after
{"type":"jwt","config":{"jwt_token_file":"/var/secrets/token.jwt"}} Defensive patterns
Strategy: validation
Validate before calling
// Ensure jwt_token_file is non-empty.
func requireJWTTokenFile(raw json.RawMessage) error {
var cfg struct {
JWTTokenFile string `json:"jwt_token_file"`
}
_ = json.Unmarshal(raw, &cfg)
if cfg.JWTTokenFile == "" {
return fmt.Errorf("jwt_token_file is required")
}
return nil
} Try / catch
if _, _, err := jwtcreds.NewCallCredentials(cfg); err != nil {
if strings.Contains(err.Error(), "jwt_token_file is required") {
// set jwt_token_file before retrying.
}
} Prevention
- Treat jwt_token_file as mandatory in your config template.
- Disable the call-creds feature flag if JWT creds are unused.
- Fail the deploy if the token file path is empty.
When it happens
Trigger: Triggered at call_creds.go:47 when cfg.JWTTokenFile == "" after parsing. The field is either omitted or explicitly empty.
Common situations: jwt_token_file field omitted from the call_creds config; field present but empty; templating left the value blank.
Related errors
- failed to unmarshal JWT call credentials config
- failed to build call credentials from bootstrap for
- failed to create JWT call credentials
- failed to build credentials bundle from bootstrap for
- failed to push new configuration
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/11064f96c280dc96.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/bootstrap/jwtcreds/call_creds.go:47
"google.golang.org/grpc/credentials/jwt"
)
// NewCallCredentials returns a new JWT token based call credentials. The input
// config must match the structure specified in gRFC A97.
//
// The caller is expected to invoke the cancel function when they are done using
// the returned call creds. This cancel function is idempotent.
func NewCallCredentials(configJSON json.RawMessage) (c credentials.PerRPCCredentials, cancel func(), err error) {
var cfg struct {
JWTTokenFile string `json:"jwt_token_file"`
}
emptyFn := func() {}
if err := json.Unmarshal(configJSON, &cfg); err != nil {
return nil, emptyFn, fmt.Errorf("failed to unmarshal JWT call credentials config: %v", err)
}
if cfg.JWTTokenFile == "" {
return nil, emptyFn, fmt.Errorf("jwt_token_file is required in JWT call credentials config")
}
callCreds, err := jwt.NewTokenFileCallCredentials(cfg.JWTTokenFile)
if err != nil {
return nil, emptyFn, fmt.Errorf("failed to create JWT call credentials: %v", err)
}
return callCreds, emptyFn, nil
}
View on GitHub (pinned to 0c51461d27)