# Using DreamFactory to Authenticate for Outside Apps

**URL:** <https://community.dreamfactory.com/t/using-dreamfactory-to-authenticate-for-outside-apps/3533>\
**Category:** Authentication & Security\
**Created:** [December 22, 2016, 6:19pm UTC](https://community.dreamfactory.com/t/using-dreamfactory-to-authenticate-for-outside-apps/3533 "2016-12-22T18:19:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jraiche](https://avatars.discourse-cdn.com/v4/letter/j/ee7513/32.png) [@jraiche](https://community.dreamfactory.com/u/jraiche)\
**Post date:** [December 22, 2016, 6:19pm UTC](https://community.dreamfactory.com/t/using-dreamfactory-to-authenticate-for-outside-apps/3533/1 "2016-12-22T18:19:26Z")

</div>

Is there a way to use the JWTs dreamfactory creates in external systems? For example, using DF JWTs created through an LDAP service to login to Drupal?

---

<div class="post-metadata">

**Author:** ![mattschaer](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/mattschaer/32/914_2.png) [@mattschaer](https://community.dreamfactory.com/u/mattschaer)\
**Post date:** [January 3, 2017, 9:16pm UTC](https://community.dreamfactory.com/t/using-dreamfactory-to-authenticate-for-outside-apps/3533/2 "2017-01-03T21:16:41Z")

</div>

@jraiche I think it would depend a lot on the claims for the [JWT](https://jwt.io/) you receive from DF. If you are interested in seeing the claims you can do a GET /user/session to retrieve the sesssion token and then head [here to decode the token string.](http://jwt.calebb.net/) Then to understand what all the claims mean I would recommend reading the [JWT RFC spec](https://tools.ietf.org/html/rfc7519). I’ll research a bit further as well to see what the possibilities are.
