GrantKeys
Defined in: src/grants.ts:116
A deployment’s grant configuration. The first key mints; every key verifies. Rotation: add the new key first, keep the old one until its grants expire, then remove it.
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new GrantKeys(keys, options?): GrantKeys;Defined in: src/grants.ts:130
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
keys |
readonly Uint8Array<ArrayBufferLike>[] |
options |
GrantKeysOptions |
Returns
Section titled “Returns”GrantKeys
Throws
Section titled “Throws”Error No key, a key that is not 32 bytes, duplicate keys, or a non-positive lifetime. A worker refuses to start rather than run with a key it misread.
Properties
Section titled “Properties”audience
Section titled “audience”readonly audience: string;Defined in: src/grants.ts:120
See GrantKeysOptions.audience.
clockSkewSeconds
Section titled “clockSkewSeconds”readonly clockSkewSeconds: number;Defined in: src/grants.ts:124
See GrantKeysOptions.clockSkewSeconds.
readonly keys: readonly Uint8Array<ArrayBufferLike>[];Defined in: src/grants.ts:118
32-byte keys, minting key first.
maxTtlSeconds
Section titled “maxTtlSeconds”readonly maxTtlSeconds: number;Defined in: src/grants.ts:122
See GrantKeysOptions.maxTtlSeconds.
Methods
Section titled “Methods”aad(kid): Uint8Array;Defined in: src/grants.ts:211
The AAD a token sealed under kid is bound to.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
kid |
Uint8Array |
Returns
Section titled “Returns”Uint8Array
keyIds()
Section titled “keyIds()”keyIds(): Promise<Uint8Array<ArrayBufferLike>[]>;Defined in: src/grants.ts:205
The key ids, in key order.
Returns
Section titled “Returns”Promise<Uint8Array<ArrayBufferLike>[]>
fromEnv()
Section titled “fromEnv()”static fromEnv(env?): GrantKeys | null;Defined in: src/grants.ts:188
Read VGI_RPC_GRANT_KEYS (comma-separated, minting key first),
VGI_RPC_GRANT_AUDIENCE and VGI_RPC_GRANT_MAX_TTL_SECONDS.
Parameters
Section titled “Parameters”| Parameter | Type | Description |
|---|---|---|
env? |
Record<string, string | undefined> |
The environment; default process.env where it exists. |
Returns
Section titled “Returns”GrantKeys | null
The configuration, or null when no key is set – grants off.
Throws
Section titled “Throws”Error A malformed key or lifetime.
parse()
Section titled “parse()”static parse(encodedKeys, options?): GrantKeys;Defined in: src/grants.ts:156
Build from standard base64 key text (padding optional), minting key first.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
encodedKeys |
Iterable<string> |
options |
GrantKeysOptions |
Returns
Section titled “Returns”GrantKeys
Throws
Section titled “Throws”Error A key that is not base64 of exactly 32 bytes.
