# Token Signature could not be verified

**URL:** <https://community.dreamfactory.com/t/token-signature-could-not-be-verified/4660>\
**Category:** Authentication & Security\
**Created:** [October 23, 2018, 6:03pm UTC](https://community.dreamfactory.com/t/token-signature-could-not-be-verified/4660 "2018-10-23T18:03:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chris](https://avatars.discourse-cdn.com/v4/letter/c/958977/32.png) [@Chris](https://community.dreamfactory.com/u/Chris)\
**Post date:** [October 23, 2018, 6:03pm UTC](https://community.dreamfactory.com/t/token-signature-could-not-be-verified/4660/1 "2018-10-23T18:03:15Z")

</div>

I am new to Dreamfactory and working on my first app. I am using Auth0 for authentication, Angular 7/ Typescript 3.1.3 for the App. It appears to be successfully passing the jwt Id\_token and proper headers with my http request to DF. I just cant seem to get past the error below.

1. error:

2. code: 401

3. context: null

4. message: “Invalid token: Token Signature could not be verified.”

Is there a setting in DF that I am not aware of? I appreciate the help and all the appropriate mocking I deserve. 🙂

---

<div class="post-metadata">

**Author:** ![Kevin\_Mcgahey](https://avatars.discourse-cdn.com/v4/letter/k/b3f665/32.png) [@Kevin\_Mcgahey](https://community.dreamfactory.com/u/Kevin_Mcgahey)\
**Post date:** [October 23, 2018, 6:39pm UTC](https://community.dreamfactory.com/t/token-signature-could-not-be-verified/4660/2 "2018-10-23T18:39:44Z")

</div>

Hi @Chris,

This error is thrown when the Session Token is not passed correctly. Can you share more info of how you are passing it? Using this forum post as reference [Invalid token: Token Signature could not be verified](https://community.dreamfactory.com/t/invalid-token-token-signature-could-not-be-verified/1773)

Best,  
Kevin McGahey

---

<div class="post-metadata">

**Author:** ![Chris](https://avatars.discourse-cdn.com/v4/letter/c/958977/32.png) [@Chris](https://community.dreamfactory.com/u/Chris)\
**Post date:** [October 23, 2018, 6:53pm UTC](https://community.dreamfactory.com/t/token-signature-could-not-be-verified/4660/3 "2018-10-23T18:53:46Z")

</div>

Thanks for the reply. Here is the code from my Auth.interceptor.

```
intercept(req: HttpRequest<any>,
          next: HttpHandler): Observable<HttpEvent<any>> {

    const idToken = localStorage.getItem("id_token");

    if (idToken) {

        const cloned = req.clone({
            setHeaders:{
  
              "Content-Type": "application/json",
              "X-Dreamfactory-Session-Token": idToken,
              "X-Dreamfactory-API-Key": this.globals.DREAMFACTORY_API_KEY
            }

        });

        return next.handle(cloned);
    }
    else {
        return next.handle(req);
    }
}

```

Here is the Header from the chrome dev tools.

 ![image](https://canada1.discourse-cdn.com/flex035/uploads/dreamfactory/original/2X/3/36e5b7ba4804300af270db1f6e3918b6e166c666.png)

---

<div class="post-metadata">

**Author:** ![Chris](https://avatars.discourse-cdn.com/v4/letter/c/958977/32.png) [@Chris](https://community.dreamfactory.com/u/Chris)\
**Post date:** [October 24, 2018, 12:34am UTC](https://community.dreamfactory.com/t/token-signature-could-not-be-verified/4660/4 "2018-10-24T00:34:27Z")

</div>

So I validated that the Session-Token was passing correctly pulling the token from local storage and from the chrome dev headers above. Here is the decoded token.

1. {iss: “[https://liquidsoft.auth0.com/](https://liquidsoft.auth0.com/)”, sub: “auth0|5bbc1ef95e09334d778a3e05”, aud: “CmFgMh0WHb8pJj5OoVVLfffP2rCCUuwZ”, iat: 1540340911, exp: 1540376911, …}

2. at\_hash: “U7Tvb9Sig91ebtE-6aMNeA”

3. aud: “CmFgMh0WHb8pJj5OoVVLfffP2rCCUuwZ”

4. exp: 1540376911

5. iat: 1540340911

6. iss: “[https://liquidsoft.auth0.com/](https://liquidsoft.auth0.com/)”

7. nonce: “N6D-DLyHAA2~6oZLOXievle4IBkegFGF”

8. sub: “auth0|5bbc1ef95e09334d778a3e05”

Is the issue that the iss is different than site making the call?
