diff --git a/internal/naisapi/auth/oidc.go b/internal/naisapi/auth/oidc.go index ce4638ce..296019eb 100644 --- a/internal/naisapi/auth/oidc.go +++ b/internal/naisapi/auth/oidc.go @@ -259,6 +259,7 @@ func (c *oidcClient) ParseIDToken(ctx context.Context, token string) (*IDToken, jwt.WithIssuer(c.oidc.Issuer), jwt.WithAudience(c.oauth2.ClientID), jwt.WithClaimValue("email_verified", true), + jwt.WithAcceptableSkew(10*time.Second), jwt.WithValidate(true), ) if err != nil {