## TL;DR

Three things to get right with external JWT auth in SurrealDB. First, the DEFINE TOKEN statement and the token header must agree on the algorithm (HS512 in this case) and the shared value.

## Steps

1. Three things to get right with external JWT auth in SurrealDB. First, the DEFINE TOKEN statement and the token header must agree on the algorithm (HS512 in this case) and the shared value. Second, the header needs the right scope claims: NS and DB for a database token, plus TK naming the defined token. Third, send it as a Bearer token on the HTTP API or through the JS client's authenticate method. If auth still fails, double check you are hitting the namespace and database the token was defined on, since a token defined ON DATABASE will not authenticate at the namespace level.

``` DEFINE TOKEN my_token ON DATABASE TYPE HS512 VALUE '1234567890'; ```

2. Then i generate a token using the above '1234567890' and following header fields.

``` { "alg": "HS512", "typ": "JWT", "NS": "help", "DB": "help", "TK": "my_token" } ```

3. Note: i have also tried defining the "NS","DB","TK" fields in the Payload section of token. Then i try to authenticate using the token in JS client and http request with your bearer credential header. ```...

## When to use

You are seeing this: Three things to get right with external JWT auth in SurrealDB. Use this skill when you run into "Authentication Failure when using external JWT token in SurrealDB".

## When not to use

If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.

## Versions

No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.

## Why this happens

The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.
