Skip to main content
The isolation matrix in this v2.7.4 source example has one incorrect row. Because JWT authorization is configured, a request without a token returns 401. It does not bypass isolation or gain access to stored data.
Build on Symmetric RBAC Basic by adding user-scoped database session isolation.
user_isolation.py

Run the Example

The source falls back to a public demonstration secret. Local demos can use it, but before exposing this server set JWT_VERIFICATION_KEY to a private random value of at least 32 bytes and use the same value to sign tokens.
1

Set up your virtual environment

2

Install dependencies

3

Export your OpenAI API key

4

Run PgVector

5

Configure the optional JWT secret

Set JWT_VERIFICATION_KEY to override the hardcoded demonstration secret used to sign and verify tokens.
6

Run the example

Save the code above as user_isolation.py, then run:
Full source: cookbook/05_agent_os/rbac/symmetric/user_isolation.py