JWT auth for Feedback & bug report widget
Currently, you can not authenticate users using the identify functionality for private organizations. Therefore, the only way to use the widgets is via JWT. The Feedback portal widget already supports this, but we need to add it to the Feedback & bug report widget as well.
Log in to comment and vote
Comments6
Aug 6, 2025
PinnedHey everyone, this post title has no longer been true for a while. I will be closing this.
You can use the Featurebase identify functionality to authenticate users from widgets, even for private organizations (as long as you have provided the
userHash).JWT can also be used for it, as in Feedback widget installation
Here is the docs for the identity verification logic: Set up Identity Verification
Jared Scheib
Aug 5, 2025
Further follow-up about the JWT:
1. Is the JWT used at SDK init permanently bound to the session?
2. Can we rotate tokens mid-session?
3. Is there a way to reauthenticate without a full SDK reinit?
4. Is my only option, besides a change on your end, to not expire the JWT throughout the session post-initialization?
5. Any other workarounds you can think of, if not those?
It appears that the JWT I'm creating is only used for the initial handshake, such as establishing a secure session, since beyond that I'm sending requests with my rotated JWT and those requests are getting 401 Unauthorized responses.
Since this is a client-to-server JWT authorization process, not having an expiry is not secure. But it looks like my only option, given the SDK's current limitations.
Could you introduce functionality to either:
1. Rotate the JWT at runtime (`sdk.setToken(...)`)
2. Renew the session without full teardown
My goal is to be able to use Private Organizations, JWT-based SSO, and set an expiry of my choosing (currently it's 5 minutes). It seems that ideally your SDK would allow me to tell it where to get a rotated JWT from, and it would use a rotated JWT any time it detects that the current JWT has expired, whenever the user clicks Submit on their Feedback via the Feedback widget.
Jared Scheib
Aug 5, 2025
It turns out that my solution to patch the SDK with an
update_jwtaction, actually doesn't work. Even though the JWT is being updated in the request we send over, we're still getting a 401 Unauthorized: "Organization is private. Please authenticate." This makes the Feedback widget with Private Organizations unusable with an expiry. I haven't tested an un-expiring JWT, as that would defeat one of the JWT's purposes of security, but that may be the only solution here aside from making our organization not Private.Jared Scheib
Aug 1, 2025
I’ve spent the day trying to hack around this, including patching the minified SDK. I added an
update_jwtcase to handleIFrameMessage for the feedback widget, and I’m calling it before our ownpostMessage()openFeedbackWidget. But even this is insufficient because within the widget you can click Post More, and your JWT may have expired. Super frustrating.Jared Scheib
Aug 1, 2025
I just confirmed within the request headers that subsequent calls to
`window.Featurebase('initialize_feedback_widget'...)`only send the original JWT that was provided upon the first call to that function, even when I call that function subsequent times and provide a new, refreshedtoken.This defeats one of the primary purposes of a JWT, which is a secure token with time-based expiry to protect our users. It appears that there is no way to refresh the JWT, so I'll have to simply remove the expiration, which is insecure.
We are currently a paying Business-tier customer. This lack of security may defeat our ability to continue with Featurebase.
Jared Scheib
Aug 1, 2025
Is this an outstanding issue? I’m not clear how to refresh the JWT for private organizations when using the Feedback widget.