# Upstream JWT authentication

**URL:** <https://discuss.konghq.com/t/upstream-jwt-authentication/9340>\
**Category:** General\
**Tags:** kong-gateway\
**Created:** [November 10, 2021, 7:28am UTC](https://discuss.konghq.com/t/upstream-jwt-authentication/9340 "2021-11-10T07:28:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sachithmuhandiram](https://avatars.discourse-cdn.com/v4/letter/s/f19dbf/32.png) [@sachithmuhandiram](https://discuss.konghq.com/u/sachithmuhandiram)\
**Post date:** [November 10, 2021, 7:28am UTC](https://discuss.konghq.com/t/upstream-jwt-authentication/9340/1 "2021-11-10T07:28:30Z")

</div>

Is there a way to secure Kong API gateway to our backend service call using JWT?

[Here](https://docs.konghq.com/hub/revolution_systems/upstream-auth-basic/) official document has basic auth config option and [this third party plugin](https://github.com/Optum/kong-upstream-jwt) has some JWT based.

Is there a way to implement JWT inbetween API server and backend?

---

<div class="post-metadata">

**Author:** ![andresgarita](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@andresgarita](https://discuss.konghq.com/u/andresgarita)\
**Post date:** [October 19, 2022, 9:19pm UTC](https://discuss.konghq.com/t/upstream-jwt-authentication/9340/2 "2022-10-19T21:19:25Z")

</div>

Hello. I have the same question. I’m looking for a way to all backend services only accept requests from Kong. I saw [Mutual Auth](https://docs.konghq.com/hub/kong-inc/mtls-auth/) plugin is capable of that, but is enterprise.
