# go-usertoken User tokens an ExApp mints for Microservices. Import `gitea.neitzel.de/konrad/go-usertoken`. ## Language **User token**: A short-lived RS256 JWT whose `sub` is the Nextcloud user id. Optional `groups` is a snapshot taken when the ExApp minted it. Microservices forward the same token to each other. _Avoid_: AppAPI secret, access token (too broad), session **Caller**: The user id, username, and optional groups read from a verified user token. _Avoid_: Requesting user (that is the AppAPI name, before a token exists), principal **Signer**: The ExApp-side minter. It holds the only private key. _Avoid_: issuer (the `iss` string), identity server **Static key**: The verify mode that checks a user token with a configured RSA public key and a fixed `iss` string. No discovery URL. _Avoid_: JWKS, OIDC **OIDC issuer**: The verify mode that discovers keys at an identity server (for example Keycloak). One Microservice process uses this mode or static key, not both. _Avoid_: running discovery on the ExApp