> For the complete documentation index, see [llms.txt](/docs/llms.txt)

# External JWT Reconcile Lambda | FusionAuth Docs

An overview of the External JWT Reconcile lambda.

# External JWT Reconcile Lambda

[Edit on GitHub](https://github.com/FusionAuth/fusionauth-site/blob/main/astro/src/content/docs/extend/code/lambdas/reconcile/external-jwt-reconcile.mdx)

[View Markdown](/docs/extend/code/lambdas/reconcile/external-jwt-reconcile.md)

When an External JWT identity provider is used to complete a federated login request, FusionAuth will use the [configured linking strategy](/docs/lifecycle/authenticate-users/identity-providers/#linking-strategies) to reconcile the user. FusionAuth will attempt to match the user information returned from the External JWT identity provider to an existing user account or create a new one.

You may optionally utilize a lambda to customize the user and user registration during the authentication event.

When you create a new lambda using the FusionAuth administrative user interface, you will be provided an empty function to implement.

Starting in version 1.65.0, you can use [attribute mappings](/docs/lifecycle/authenticate-users/identity-providers/#attribute-mappings) to map IdP claims directly to FusionAuth user and registration fields without writing a lambda. Reconcile lambdas and attribute mappings are mutually exclusive. Attempting to configure both on a given IdP results in a validation error.

## Lambda Structure[#](#lambda-structure)

If you are using the API to create the lambda you will need to ensure your function has the following signature:

```javascript
function reconcile(user, registration, jwt, context)  {
  // Lambda code goes here
}
```

This lambda must contain a function named `reconcile` that accepts the following parameters:

*   `user` - the FusionAuth User object. You can modify this object. However, the **email** and **username** attributes may not be modified after the user has been linked.
*   `registration` - the FusionAuth UserRegistration object. You can modify this object.

*   `jwt` - the JSON payload returned by the external identity provider JWT. This object is read-only.
*   `context` - Available since 1.64.0 - an object containing the context of the request, including access to [secrets](/docs/extend/code/lambdas#secrets). This object is read-only.

The two FusionAuth objects are well documented in the [User API](/docs/apis/users) and [Registration API](/docs/apis/registrations) documentation. The `jwt` may contain various user claims to utilize during the reconcile process.

## Assigning The Lambda[#](#assigning-the-lambda)

Once a lambda is created, you may assign it to the External JWT identity provider in the IdP configuration.

Navigate to Settings -> Identity Providers and select your existing External JWT configuration or click Add provider and select External JWT if it has not yet been configured.

## Example Lambda[#](#example-lambda)

The following is a simple example of an External JWT reconcile lambda. You will need to modify it to suit your needs.

```javascript
// This is an example External JWT reconcile, modify this to your liking.
function reconcile(user, registration, jwt) {
  // User claims
  user.firstName = jwt.first_name;
  user.lastName = jwt.last_name;
  user.birthDate = jwt.birth_date;
  user.imageUrl = jwt.image_url;
  user.data = user.data || {};
  user.data['email'] = jwt.email;

  // Registration claims
  registration.data = registration.data || {};
  registration.data['iss'] = jwt.iss;
}
```