If your JWT token provider is OAuth 2.0 compliant, you can configure the OAuth2FeignRequestInterceptor, with an OAuth2ProtectedResourceDetails object. This object is the base class for all OAuth 2.0 grant type information. In your case, I recommend using ResourceOwnerPasswordResourceDetails instead. This will allow you to configure an interceptor using a username and password.

@Configuration
public class OAuth2RequestInterceptorConfiguration {

    @Bean
    public OAuth2FeignRequestInterceptor requestInterceptor() {
        OAuth2ClientContext clientContext = new DefaultOAuth2ClientContext();
        OAuth2ProtectedResourceDetails resourceDetails =
            new ResourceOwnerPasswordResourceDetails();
        resourceDetails.setUsername("username");
        resourceDetails.setPassword("password");
        return new OAuth2FeignRequestInterceptor(clientContext, resourceDetails);
    }
}

For other cases, you will need to create your own RequestInterceptor

public class MyRequestInterceptor implements RequestInterceptor {

    private String jwt;
    private LocalDateTime expirationDate;

    @Override
    public void apply(RequestTemplate requestTemplate) {
        /* validate and refresh your token, this sample is not thread safe */
        if (LocalDateTime.now().isAfter(expirationDate)) {
            requestToken();
        }

        /* use the token */
        requestTemplate.header("Authorization: Bearer " + this.jwt);
    }
}
Answer from Kevin Davis on Stack Overflow
🌐
Medium
medium.com › @IlyasKeser › feignclient-interceptor-for-bearer-token-oauth-f45997673a1
FeignClient Interceptor for Bearer Token/OAuth | by Ilyas Keser | Medium
October 20, 2019 - @FeignClient(name = "userClient", ... want. We can implement an interceptor and provide the token for all Feign clients under the hood and remove the parameter in method signature....
🌐
GitHub
github.com › int128 › feign-oauth2-example › blob › master › README.md
feign-oauth2-example/README.md at master · int128/feign-oauth2-example
Make a request with the access token. curl -v -H 'Authorization: Bearer 50480ab0-4616-449c-823b-e5eb41ebe44f' \ http://localhost:8081/hello
Author: int128
🌐
Baeldung
baeldung.com › home › spring › spring cloud › provide an oauth2 token to a feign client
Provide an OAuth2 Token to a Feign Client | Baeldung
March 26, 2025 - Adding interceptors is a useful feature provided by Feign. We’ll use a RequestInterceptor, which injects the OAuth2 access token into the request of the OpenFeign client by adding an Authorization Bearer header.
🌐
Medium
medium.com › @sachinsindhu › auth-token-refesh-using-feign-error-decoder-and-retryer-398368cf15a6
Auth Token refesh using feign error decoder , retryer and request interceptor | by Sachin Sindhu | Medium
September 19, 2023 - @RequiredArgsConstructor public class CustomRequestInterceptor implements RequestInterceptor { private final TokenRepository tokenRepository; private final LoginService loginService; @Override public void apply(RequestTemplate template) { // we can provide intercepting logic factory to handle each feign client seperately // here we are considering only single client so hard coding to work for ServiceAClient client only if (template.feignTarget().type().equals(ServiceAClient.class)) { Token token = tokenRepository.findToken("unique token identifier here"); if (token == null || Status.Expired.equals(token.getStatus())) { token = loginService.login(); } template.header("Authorization", "Bearer " + token.getToken()); } } }
Top answer
1 of 3
7

If your JWT token provider is OAuth 2.0 compliant, you can configure the OAuth2FeignRequestInterceptor, with an OAuth2ProtectedResourceDetails object. This object is the base class for all OAuth 2.0 grant type information. In your case, I recommend using ResourceOwnerPasswordResourceDetails instead. This will allow you to configure an interceptor using a username and password.

@Configuration
public class OAuth2RequestInterceptorConfiguration {

    @Bean
    public OAuth2FeignRequestInterceptor requestInterceptor() {
        OAuth2ClientContext clientContext = new DefaultOAuth2ClientContext();
        OAuth2ProtectedResourceDetails resourceDetails =
            new ResourceOwnerPasswordResourceDetails();
        resourceDetails.setUsername("username");
        resourceDetails.setPassword("password");
        return new OAuth2FeignRequestInterceptor(clientContext, resourceDetails);
    }
}

For other cases, you will need to create your own RequestInterceptor

public class MyRequestInterceptor implements RequestInterceptor {

    private String jwt;
    private LocalDateTime expirationDate;

    @Override
    public void apply(RequestTemplate requestTemplate) {
        /* validate and refresh your token, this sample is not thread safe */
        if (LocalDateTime.now().isAfter(expirationDate)) {
            requestToken();
        }

        /* use the token */
        requestTemplate.header("Authorization: Bearer " + this.jwt);
    }
}
2 of 3
4

You can try with something like:

public class FeignConfiguration {

    @Value("${security.jwt.token}")
    private String jwtToken;

    @Bean
    public RequestInterceptor requestInterceptor() {
        @Override
        public void apply(RequestTemplate requestTemplate) {
            requestTemplate.header("Authorization", jwtToken);
        }
    }
}
Top answer
1 of 1
2

Edit

@FeignClient is now in maintenance mode, replaced by RestClient and HttpServiceProxyFactory. See below.

Authorizing @FeignClient requests

Use a RequestInterceptor to automatically add the authorization header.

With OAuth2, two strategies:

  • use the token already in the security context, but this requires that the following two conditions are met:
    1. the application sending the REST call is an oauth2ResourceServer - not an app configured with oauth2Login, the security of which is based on session cookies, not on Bearer tokens
    2. the request is sent on behalf of the resource owner of the "parent" request
  • configure the calling application as an OAuth2 client (additionally to OAuth2 resource server if it is a REST API with requests authorized with Bearer tokens) and use the OAuth2AuthorizedClientManager to get a new token

In Spring Boot apps, request interceptors decorated with @Component in the same package or any sub-package of the @Configuration with @EnableFeignClients are auto-detected: no need for explicit conf.

@FeignClient reusing the access token in the security context of an oauth2ResourceServer application

@Component
public class ForwardingBearerRequestInterceptor implements RequestInterceptor {

    @Override
    public void apply(RequestTemplate template) {
        final var auth = SecurityContextHolder.getContext().getAuthentication();
        if (auth instanceof JwtAuthenticationToken jwtAuth) {
            template.header(HttpHeaders.AUTHORIZATION, "Bearer %s".formatted(jwtAuth.getToken().getTokenValue()));
        }
    }
}

@FeignClient getting a new access token using an OAuth2 client registration

This applies in two scenarios:

  • the calling application is configured with oauth2Login. As a reminder, such applications are OAuth2 clients and the request they receive are authorized with session cookies. So there is no access token to forward in the security context. Tokens are in session and we access them using the OAuth2AuthorizedClientManager.
  • the calling application is configured with oauth2ResourceServer, but we need to use another client registration than the one used to get the token authorizing the incoming request. This happens for instance when the calling service uses the same client credentials, whoever sent the original request.
@Component
@RequiredArgsConstructor
public class OAuth2RegistrationRequestInterceptor implements RequestInterceptor {
    private final OAuth2AuthorizedClientManager authorizedClientManager;

    @Override
    public void apply(RequestTemplate template) {
        final var auth = SecurityContextHolder.getContext().getAuthentication();
        OAuth2AuthorizeRequest authorizeRequest = OAuth2AuthorizeRequest.withClientRegistrationId("some-registration-id").principal(auth).build();
        final var authorizedClient = Optional.ofNullable(authorizedClientManager.authorize(authorizeRequest));
        authorizedClient.ifPresent(ac -> template.header(HttpHeaders.AUTHORIZATION, "Bearer %s".formatted(ac.getAccessToken().getTokenValue())));
    }
}

Using RestClient and HttpServiceProxyFactory

Spring Cloud put @FeignClient in maintenance mode when Spring Core introduced the HttpServiceProxyFactory for RestClient and WebClient, which serves the same purpose for declarative REST clients.

Configuration for OAuth2 authorization is a little more verbose. For this reason, I created a tiny Boot starter for it. Sample usage:

Provided that we have the following @HttpExchange describing the REST service to consume (I have those generated from OpenAPI specs):

@HttpExchange(accept = MediaType.APPLICATION_JSON_VALUE)
public interface KeycloakAdminApi {

    @GetExchange(url = "/{realm}/users/count")
    Long getTotalUsersCount(@PathVariable(name = "realm") String realm);
}

We can have the implementation generated to consume the remote REST service with the following:

@Bean
KeycloakAdminApi keycloakAdminApi(SpringAddonsRestClientSupport restSupport) {
    return restSupport.service("keycloak-admin-api", KeycloakAdminApi.class);
}

The configuration for the endpoint base-URL, authorization (Basic or OAuth2), and optionally for HTTP proxy, is done in application properties:

com:
  c4-soft:
      rest:
        client:
          keycloak-admin-api:
            base-url: ${keycloak-base-uri}/admin/realms
            authorization:
              oauth2:
                forward-bearer: true

The above re-uses the incoming Bearer token on an oauth2ResourceServer. See the doc for using a new token issued for any registration.

It is published on maven-central:

<dependency>
    <groupId>com.c4-soft.springaddons</groupId>
    <artifactId>spring-addons-starter-rest</artifactId>
    <version>7.8.10</version>
</dependency>
🌐
Springcloud
springcloud.io › post › 2022-01 › feign-token-relay
Spring Cloud Feign implements JWT token relay to deliver authentication information - Spring Cloud
January 12, 2022 - If we don’t turn on fault tolerance we can extract the authentication object JwtAuthenticationToken from the Spring Security provided SecurityContext object to the resource server which contains the JWT token and then we can implement Feign’s interceptor interface RequestInterceptor to place the token in the request header, with the following pseudo-code.
🌐
GitHub
github.com › spring-attic › spring-cloud-security › issues › 87
Feign request interceptor and security context · Issue #87 · spring-attic/spring-cloud-security
December 23, 2015 - @Bean public RequestInterceptor requestTokenBearerInterceptor() { return new RequestInterceptor() { @Override public void apply(RequestTemplate requestTemplate) { OAuth2AuthenticationDetails details = (OAuth2AuthenticationDetails) SecurityContextHolder.getContext().getAuthentication().getDetails(); requestTemplate.header("Authorization", "bearer " + details.getTokenValue()); } }; } This one executs, but it seems that this is triggered in different thread and context does not have any authentication. Line before invoking my feign client context is present.
Author: spring-attic
🌐
Javadoc.io
javadoc.io › doc › org.springframework.cloud › spring-cloud-security › 2.2.0.RELEASE › org › springframework › cloud › security › oauth2 › client › feign › OAuth2FeignRequestInterceptor.html
OAuth2FeignRequestInterceptor - spring-cloud-security 2.2.0.RELEASE javadoc
Bookmarks · Latest version of org.springframework.cloud:spring-cloud-security · https://javadoc.io/doc/org.springframework.cloud/spring-cloud-security · Current version 2.2.0.RELEASE · https://javadoc.io/doc/org.springframework.cloud/spring-cloud-security/2.2.0.RELEASE · package-list path ...
Find elsewhere
Top answer
1 of 1
5

Thanks to this comment, I managed to tidy up my implementation a little bit. So no more need for specifying encode/decoder nonsense, or having to manually build my Feign client.

The docs here provide some info, but as is typical they are a bit thin on concrete examples, so perhaps the below will help someone else. Note: I'm using spring boot, and including feign like so in build.gradle implementation 'org.springframework.cloud:spring-cloud-starter-openfeign'

First, create the RequestInterceptor like so:

import org.springframework.context.annotation.Bean;
import org.springframework.security.core.Authentication;
import org.springframework.security.core.context.SecurityContextHolder;
import org.springframework.security.oauth2.jwt.Jwt;

import feign.RequestInterceptor;
import lombok.extern.slf4j.Slf4j;

/**
 * A Feign configuration to add the incoming Bearer token to an outgoing feign client request.
 * Only annotate this class with "@Configuration" if you want this interceptor to apply globally to all your Feign clients.
 * Otherwise you risk exposing the auth token to a third party, or adding it unnecessarily to requests that don't need it.
 */
@Slf4j
public class BearerAuthFeignConfig {

    @Bean
    public RequestInterceptor bearerAuthRequestInterceptor() {
        return requestTemplate -> {
            Authentication authentication = SecurityContextHolder.getContext().getAuthentication();
            if (authentication != null && authentication.getPrincipal() instanceof Jwt) {
                Jwt jwt = (Jwt) authentication.getPrincipal();
                requestTemplate.header("Authorization", "Bearer " + jwt.getTokenValue());
            } else {
                log.error("Unable to add Authoriation header to Feign requestTemplate");
            }
        };
    }
}

Then when declaring your feign client, pass the configuration

@FeignClient(
    name = "my-client-that-needs-the-auth",
    configuration = BearerAuthFeignConfig.class,
    url = "http://whatever.com"
)
public interface PlayerManagementClient {
  ...

You'll also need the @EnableFeignClients annotation on your @SpringBootApplication class

Top answer
1 of 3
25

You don't really need your own implementation of the FeignRequestInterceptor as there is already BasicAuthRequestInterceptor in the feign.auth package that does exactly the same.

That being said, you basically have almost everything set up already. All is left to do is to define the basicAuthRequestInterceptor bean with specific username and password:

@Bean
public RequestInterceptor basicAuthRequestInterceptor() {
    return new BasicAuthRequestInterceptor("username", "password");
}
2 of 3
11

I know the thread is a bit old but wanted to give some explanation on what's happening here.

If you'd like to customize your Feign requests, you can use a RequestInterceptor. This can be a custom implementation or you can reuse what's available in the Feign library, e.g. BasicAuthRequestInterceptor.

How to register it? Well, there are 2 ways to do it depending on how you use Feign.

If you're using plain Feign without Spring, then you gotta set the interceptor to the Feign builder. An example is here.

Feign.builder()
     .requestInterceptor(new MyCustomInterceptor())
     .target(MyClient.class, "http://localhost:8081");

If you're using Spring Cloud OpenFeign and you use the @FeignClient annotation to construct your clients, then you have to create a bean from your RequestInterceptor by either defining it as a @Component or as a @Bean in one of your @Configuration classes. Example here.

@Component
public class MyCustomInterceptor implements RequestInterceptor {
    @Override
    public void apply(RequestTemplate template) {
        // do something
    }
}

Also, you can check out one of my articles in this topic, maybe that clears it up better: Customizing each request with Spring Cloud Feign

🌐
Google Groups
groups.google.com › g › quarkus-dev › c › _wn2xq1FwA8
Implementation similar to Feign's RequestInterceptor with MicroProfile RestClient
HttpBinService bookResource = Feign.builder().encoder(new JacksonEncoder()) .decoder(new JacksonDecoder()).requestInterceptor(interceptor) .target(HttpBinService.class, HTTP_BIN_URL); template.header("Authorization", "Bearer " + bookResource.getAuthenticatedUser().getAccess_token()); } } @Headers("Content-Type: application/x-www-form-urlencoded") public interface HttpBinService { @RequestLine("POST /token?grant_type=client_credentials") AuthStatus getAuthenticatedUser(); } With that I don't need to call my authentication service every time I need to call my business service.
Top answer
1 of 2
6

According documentation need use AuthorizedClientServiceOAuth2AuthorizedClientManager instead of DefaultOAuth2AuthorizedClientManager

When operating outside of the context of a HttpServletRequest, use AuthorizedClientServiceOAuth2AuthorizedClientManager instead.

2 of 2
5

So. I was playing with your solution in my free time. And found the simple solution:

just add SecurityContextHolder.getContext().authentication principle to your code OAuth2AuthorizeRequest request = OAuth2AuthorizeRequest.withClientRegistrationId(appClientId).build();

Should be like this:

val request = OAuth2AuthorizeRequest
                .withClientRegistrationId("keycloak") // <-- here your registered client from application.yaml
                .principal(SecurityContextHolder.getContext().authentication)
                .build()

Used packages:

implementation("org.springframework.boot:spring-boot-starter-web")
implementation("org.springframework.cloud:spring-cloud-starter-openfeign")
implementation("org.springframework.boot:spring-boot-starter-oauth2-client")

application.yaml:

spring:
  security:
    oauth2:
      client:
        registration:
          keycloak: # <--- It's your custom client. I am using keycloak
            client-id: ${SECURITY_CLIENT_ID}
            client-secret: ${SECURITY_CLIENT_SECRET}
            authorization-grant-type: client_credentials
            scope: openid # your scopes
        provider:
          keycloak: # <--- Here Registered my custom provider
            authorization-uri: ${SECURITY_HOST}/auth/realms/${YOUR_REALM}/protocol/openid-connect/authorize
            token-uri: ${SECURITY_HOST}/auth/realms/${YOUR_REALM}/protocol/openid-connect/token

feign:
  compression:
    request:
      enabled: true
      mime-types: application/json
    response:
      enabled: true
  client.config.default:
    connectTimeout: 1000
    readTimeout: 60000
    decode404: false
    loggerLevel: ${LOG_LEVEL_FEIGN:basic}

SecurityConfiguration:

@Configuration
@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true)
class SecurityConfiguration() : WebSecurityConfigurerAdapter() {

    @Throws(Exception::class)
    override fun configure(http: HttpSecurity) {
        // @formatter:off
        http
                .authorizeRequests { authorizeRequests ->
                    authorizeRequests
                            .antMatchers(HttpMethod.GET, "/test").permitAll() // Here my public endpoint which do logic with secured client enpoint
                            .anyRequest().authenticated()
                }.cors().configurationSource(corsConfigurationSource()).and()
                .csrf().disable()
                .cors().disable()
                .httpBasic().disable()
                .formLogin().disable()
                .logout().disable()
                .oauth2Client()
        // @formatter:on
    }

    @Bean
    fun authorizedClientManager(
            clientRegistration: ClientRegistrationRepository?,
            authorizedClient: OAuth2AuthorizedClientRepository?
    ): OAuth2AuthorizedClientManager? {
        val authorizedClientProvider = OAuth2AuthorizedClientProviderBuilder
                .builder()
                .clientCredentials()
                .build()
        val authorizedClientManager = DefaultOAuth2AuthorizedClientManager(clientRegistration, authorizedClient)
        authorizedClientManager.setAuthorizedClientProvider(authorizedClientProvider)
        return authorizedClientManager
    }

}

FeignClientConfiguration:

private val logger = KotlinLogging.logger {}

class FeignClientConfiguration(private val authorizedClientManager: OAuth2AuthorizedClientManager) {

    @Bean
    fun requestInterceptor(): RequestInterceptor = RequestInterceptor { template ->
        if (template.headers()["Authorization"].isNullOrEmpty()) {
            val accessToken = getAccessToken()
            logger.debug { "ACCESS TOKEN TYPE: ${accessToken?.tokenType?.value}" }
            logger.debug { "ACCESS TOKEN: ${accessToken?.tokenValue}" }
            template.header("Authorization", "Bearer ${accessToken?.tokenValue}")
        }
    }

    private fun getAccessToken(): OAuth2AccessToken? {
        val request = OAuth2AuthorizeRequest
                .withClientRegistrationId("keycloak") // <- Here you load your registered client
                .principal(SecurityContextHolder.getContext().authentication)
                .build()
        return authorizedClientManager.authorize(request)?.accessToken
    }

}

TestClient:

@FeignClient(
        name = "test",
        url = "http://localhost:8080",
        configuration = [FeignClientConfiguration::class]
)
interface TestClient {
    @GetMapping("/test")
    fun test(): ResponseEntity<Void> // Here my secured resource server endpoint. Expect 204 status
}
🌐
javathinking
javathinking.com › blog › provide-an-oauth2-token-to-a-feign-client
Provide an OAuth2 Token to a Feign Client — javathinking.com
For example, in your configuration class, add a method that returns the interceptor: java @Bean public OAuth2FeignRequestInterceptor oAuth2FeignRequestInterceptor( OAuth2AuthorizedClientManager authorizedClientManager) { return new OAuth2FeignRequestInterceptor(authorizedClientManager); } Then, in your Feign client interface, you can use the @RequestHeader annotation to include the token: java @FeignClient(name = "protected-service", contextId = "protected-service") public interface ProtectedServiceFeignClient { @GetMapping("/protected-resource") String getProtectedResource(); } Once the OAuth
🌐
GitHub
github.com › spring-cloud › spring-cloud-netflix › issues › 159
Request Interceptors can't be add to the Feign builder · Issue #159 · spring-cloud/spring-cloud-netflix
January 18, 2015 - I want to use Feign together with spring cloud security especially with @EnableOAuth2Resource. When I request a resource with feign I got a 401. The reason is, that feign didn't include a token in the header. I created a request intercep...
Author: spring-cloud
Top answer
1 of 1
1

To collect the token with Feign you need the following:

import java.util.Map;
import feign.codec.Encoder;
import feign.form.spring.SpringFormEncoder;

import org.springframework.beans.factory.ObjectFactory;
import org.springframework.boot.autoconfigure.http.HttpMessageConverters;
import org.springframework.cloud.netflix.feign.FeignClient;
import org.springframework.cloud.netflix.feign.support.SpringEncoder;
import org.springframework.context.annotation.Bean;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestBody;
import static org.springframework.http.MediaType.APPLICATION_FORM_URLENCODED_VALUE;

@FeignClient(name = "oauth2", url = "https://dev-XXXXXX.okta.com/oauth2/default/v1")
public interface TokenFetcher {

    @PostMapping(value = "/token", consumes = APPLICATION_FORM_URLENCODED_VALUE)
    String token(@RequestBody Map<String, ?> form);

    class Configuration {
        @Bean
        Encoder feignFormEncoder(ObjectFactory<HttpMessageConverters> converters) {
            return new SpringFormEncoder(new SpringEncoder(converters));
        }
    }
}

Use the client like this:

@Autowired
TokenFetcher tokenFetcher;

public void test() {
    Map<String, Object> form = new HashMap<>();
    form.put("client_id", "xxxxxx");
    form.put("client_secret", "xxxxxx");
    form.put("grant_type", "client_credentials");
    String jwt = tokenFetcher.token(form);
}

Dependencies are:

<dependency>
    <groupId>org.springframework.cloud</groupId>
    <artifactId>spring-cloud-starter-feign</artifactId>
    <version>1.4.7.RELEASE</version>
</dependency>
<dependency>
    <groupId>io.github.openfeign.form</groupId>
    <artifactId>feign-form-spring</artifactId>
    <version>3.8.0</version>
</dependency>
<dependency>
    <groupId>org.springframework</groupId>
    <artifactId>spring-web</artifactId>
</dependency>

In order to use the token you must to add it token as the 'authorization' header with a prefix of 'Bearer ' (note the space) on each call. The easiest way to do this is be adding a RequestInterceptor to your FeignClient as follows:

public class FeignConfiguration {

@Bean
public RequestInterceptor requestInterceptor() {
    @Override
    public void apply(RequestTemplate requestTemplate) {
        String jwtTokenStoredSomewhere = null;
        if (requestTemplate.request().url().startsWith("https://site1")) {
            jwtTokenStoredSomewhere = site1JwtTokenStoredSomewhere;
        } else if (requestTemplate.request().url().startsWith("https://site2")) {
            jwtTokenStoredSomewhere = site2JwtTokenStoredSomewhere;
        } else {
            jwtTokenStoredSomewhere = site3JwtTokenStoredSomewhere;
        }
        requestTemplate.header("Authorization", "Bearer " + jwtTokenStoredSomewhere);
    }
}

}

🌐
Medium
medium.com › @aravindcsebe › mastering-feign-requestinterceptor-from-authentication-to-advanced-use-cases-d78fad055af5
Mastering Feign RequestInterceptor: From Authentication to Advanced Use Cases | by Spring Boot Simplified | Medium
February 9, 2026 - @FeignClient( name = "serviceAClient", url = "http://localhost:8080", configuration = ServiceAFeignConfig.class ) public interface ServiceAClient { @GetMapping("/serviceA/hello") String callServiceA(); } @Configuration public class ServiceAFeignConfig { @Bean public RequestInterceptor serviceAAuthInterceptor() { return template -> template.header("X-Auth-Token", "service-a-token"); } } You can chain multiple interceptors together: @Configuration public class FeignConfig { @Bean public RequestInterceptor authInterceptor() { return new AuthInterceptor(); } @Bean public RequestInterceptor loggingInterceptor() { return new LoggingInterceptor(); } @Bean public RequestInterceptor correlationIdInterceptor() { return new CorrelationIdInterceptor(); } } Execution Order: Interceptors are executed in the order they’re registered as beans.
🌐
Ordina-jworks
ordina-jworks.github.io › microservices › 2018 › 11 › 02 › Inter-service-communication.html
Communication in a distributed system with OpenFeign: Tips & Tricks - Kevin Van Houtte &mdash; Ordina JWorks Tech Blog
November 2, 2018 - When you want to send basic credentials you can just add an interceptor for the OpenFeign client and add the username and password. For only Bearer token communication, you can just pass it down in the request header of your method call.
🌐
Baeldung
baeldung.com › home › rest › setting request headers using feign
Setting Request Headers Using Feign | Baeldung
March 25, 2026 - Let’s try this out by implementing an AuthorisationService which we’ll use to generate the authorization token: public class ApiAuthorisationService implements AuthorisationService { @Override public String getAuthToken() { return "Bearer " + UUID.randomUUID(); } } Now, let’s implement our custom request interceptor: