Skip to main content

Caddy User Identity

set user identity selects the value returned as Caddy's user ID after successful authorization. It changes request metadata, not the token's claims, the local account record, or access permissions.

# Inside the policy; choose one setting.
set user identity subject
ValueCaddy user ID
email (default)Email, falling back to subject when email is absent
subject or subJWT sub
idJWT jti claim ID

id therefore identifies a token's claim set, not a durable user identifier. Do not use it to key an application account. For external issuers, bind a subject to its trusted issuer namespace before mapping application users.

The other identity placeholders remain available when supplied. Apply role/claim rules separately; displaying an email or subject does not grant permission to access the application.