Skip to main content
Read the JWT from an HTTP-only auth_token cookie with TokenSource.COOKIE instead of the Authorization header.
with_cookie.py

Run the Example

The source falls back to a public demonstration secret. Local demos can use it, but before exposing this server set JWT_VERIFICATION_KEY to a private random value of at least 32 bytes and use the same value to sign tokens.
1

Set up your virtual environment

2

Install dependencies

3

Export your OpenAI API key

4

Run PgVector

5

Configure the optional JWT secret

Set JWT_VERIFICATION_KEY to override the hardcoded demonstration secret used to sign and verify tokens.
6

Run the example

Save the code above as with_cookie.py, then run:
Full source: cookbook/05_agent_os/rbac/symmetric/with_cookie.py