# JWT Authentication

**URL:** <https://forums.plex.tv/t/jwt-authentication/931646>\
**Category:** Dev/API Corner\
**Tags:** other-dev, pms-api\
**Created:** [September 23, 2025, 9:09pm UTC](https://forums.plex.tv/t/jwt-authentication/931646 "2025-09-23T21:09:00Z")\
**Posts on this page:** 10\
**Page:** 2

<div class="post-metadata">

**Author:** ![SwiftPanda16](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/swiftpanda16/32/81839_2.png) [@SwiftPanda16](https://forums.plex.tv/u/SwiftPanda16)\
**Post date:** [October 1, 2025, 3:40pm UTC](https://forums.plex.tv/t/jwt-authentication/931646/21 "2025-10-01T15:40:20Z")

</div>

Thanks @marcelopazzo, this answers my original question regarding the need for a legacy Plex token.

However, I am unable to get the Plex JWT from the last step.

> [@marcelopazzo](#):
>
> Now, exchange the Pin by the auth token, providing a valid signed JWT of your device:
> 
> ```auto
> GET https://clients.plex.tv/api/v2/pins/<pinID>?deviceJWT=<signedJWT>
> 
> ```

After the user signs in to the Plex login page (from the auth url), I query the pin endpoint with my signed device JWT, but there is no Plex JWT in the response.

* * *

> [@McWanke](#):
>
> This has been created. Not sure who applied it to this post, but there is now a forum tag available for `pms-api` !

Thanks, @BigWheel edited the tags for me. 🙂

---

<div class="post-metadata">

**Author:** ![marcelopazzo](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/marcelopazzo/32/208476_2.png) [@marcelopazzo](https://forums.plex.tv/u/marcelopazzo)\
**Post date:** [October 1, 2025, 6:05pm UTC](https://forums.plex.tv/t/jwt-authentication/931646/22 "2025-10-01T18:05:08Z")

</div>

> [@SwiftPanda16](#):
>
> After the user signs in to the Plex login page (from the auth url), I query the pin endpoint with my signed device JWT, but there is no Plex JWT in the response.

Did you get any error, or just a plain legacy token in the `authToken` field? If any fields are missing in the device JWT provided, the endpoint should return an error message with the details.

---

<div class="post-metadata">

**Author:** ![SwiftPanda16](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/swiftpanda16/32/81839_2.png) [@SwiftPanda16](https://forums.plex.tv/u/SwiftPanda16)\
**Post date:** [October 1, 2025, 7:06pm UTC](https://forums.plex.tv/t/jwt-authentication/931646/23 "2025-10-01T19:06:58Z")

</div>

I kept getting a legacy token in the `authToken` field.

After more fiddling around, I think I found the problem. The pin endpoint

```auto
GET https://clients.plex.tv/api/v2/pins/<pinID>?deviceJWT=<signedJWT>

```

does not work with a JSON response. As soon as I remove the `Accept: application/json` header and use the XML response it is working and I get the Plex JWT in the `authToken` field.

* * *

Second question, does this Plex JWT authentication method work with the 4 digit code method used at `https://plex.tv/link` (i.e. without `strong=true`) instead of using the auth URL?

---

<div class="post-metadata">

**Author:** ![marcelopazzo](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/marcelopazzo/32/208476_2.png) [@marcelopazzo](https://forums.plex.tv/u/marcelopazzo)\
**Post date:** [October 2, 2025, 12:47am UTC](https://forums.plex.tv/t/jwt-authentication/931646/25 "2025-10-02T00:47:06Z")

</div>

> [@SwiftPanda16](#):
>
> Second question, does this Plex JWT authentication method work with the 4 digit code method used at `https://plex.tv/link` (i.e. without `strong=true`) instead of using the auth URL?

Should work the same, it’s meant to allow anything, including TV apps, to use JWT tokens.

I’ll review the endpoint to see what’s going on with the json response. Thanks for finding that out! :plexheart:

---

<div class="post-metadata">

**Author:** ![SwiftPanda16](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/swiftpanda16/32/81839_2.png) [@SwiftPanda16](https://forums.plex.tv/u/SwiftPanda16)\
**Post date:** [October 2, 2025, 2:07am UTC](https://forums.plex.tv/t/jwt-authentication/931646/26 "2025-10-02T02:07:16Z")

</div>

Using the 4 digit code also just returns a legacy token (using either JSON or XML responses).

---

<div class="post-metadata">

**Author:** ![marcelopazzo](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/marcelopazzo/32/208476_2.png) [@marcelopazzo](https://forums.plex.tv/u/marcelopazzo)\
**Post date:** [October 8, 2025, 8:21pm UTC](https://forums.plex.tv/t/jwt-authentication/931646/27 "2025-10-08T20:21:32Z")

</div>

Sorry for the delay in getting back to you, but with a 4-digit code, you will need to use the [http://plex.tv/link](http://plex.tv/link) interface instead of the /auth page. Is there any scenario where we need to use a short pin on the /auth interface?

---

<div class="post-metadata">

**Author:** ![SwiftPanda16](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/swiftpanda16/32/81839_2.png) [@SwiftPanda16](https://forums.plex.tv/u/SwiftPanda16)\
**Post date:** [October 8, 2025, 8:30pm UTC](https://forums.plex.tv/t/jwt-authentication/931646/28 "2025-10-08T20:30:01Z")

</div>

I am entering the 4-digit code on [https://plex.tv/link](https://plex.tv/link).

---

<div class="post-metadata">

**Author:** ![SwiftPanda16](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/swiftpanda16/32/81839_2.png) [@SwiftPanda16](https://forums.plex.tv/u/SwiftPanda16)\
**Post date:** [October 8, 2025, 9:40pm UTC](https://forums.plex.tv/t/jwt-authentication/931646/29 "2025-10-08T21:40:24Z")

</div>

I think everything is actually working properly. Both XML and JSON and both OAuth or 4-digit code.

I needed to generate a completely new client identifier and keypair to properly do a clean test of each method. Trying to reuse the same client identifier or keypair when swapping between XML and JSON or between OAuth and 4-digit code causes issues.

---

<div class="post-metadata">

**Author:** ![acod92](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@acod92](https://forums.plex.tv/u/acod92)\
**Post date:** [November 17, 2025, 5:04pm UTC](https://forums.plex.tv/t/jwt-authentication/931646/30 "2025-11-17T17:04:29Z")

</div>

Any plans to actually implement API level keys? similar to how other platforms do it? for example, currently in WatchState which is a tool that allow plex server owner to sync their user play state rely on admin token to generate sub tokens for users which has access to plex server.

Ideally, there will be API keys that could be used with tools and users are identified by their IDs and their data accessed that way.

Plex currently has:

1- main user

2- home users

3- users whom have access to the server

generating keys and tokens and trying to keep all of those in sync is rather difficult. Also,

Also i am not sure if this is the case, but users who has access to the server who aren’t home users, are supposed to be different account yeah? if so isn’t uploading pubkey to their account kind expose them to more security issues?

currently tokens are tied to the server not an account afaik

---

<div class="post-metadata">

**Author:** ![m7eesn](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/m7eesn/32/101990_2.png) [@m7eesn](https://forums.plex.tv/u/m7eesn)\
**Post date:** [December 11, 2025, 10:49am UTC](https://forums.plex.tv/t/jwt-authentication/931646/31 "2025-12-11T10:49:44Z")

</div>

Hello, i have few questions

1- is the old auth system going to be removed or are we able to use it and ignore JWT?

2- Can we have more endpoints that supports this JWT system? currently during my testing for full implementation i have run into many issues.

- There is no way to know if a clientid/pubkey is already enrolled except an error message during enrollment. Which also has problems as its checks the clientid only not the pubkey.
- No endpoint to remove old key, use case a user removed the keys by mistake etc he cant re-enroll automatically even deleting the client from the account still references the old pubkey.
- Its not explained how to handle multi-user setup with the new auth system.
- 
  - lets say we enroll the main admin user account does that mean the key know has access to generate auth requests for all home/users and all the people who has been invited to the server? or do we have to generate enrollment for each?
  - If we have to enroll all of servers sub users can we use same privkey/pubkey or we need to generate for each?

Honestly all of these issues would have been avoided if you provided server API keys like the rest of the industry using this multitiered auth system is confusing when you have many factors to consider a user account here could mean 1 user or all home users or users who has access to a server.

There are so many unknowns i hope that you dont shutdown the old authentication system until all these issues has been worked out.

[Previous page](https://forums.plex.tv/t/jwt-authentication/931646.md?page=1)
