Skip to content

GrantKeys

Defined in: src/grants.ts:116

A deployment’s grant configuration. The first key mints; every key verifies. Rotation: add the new key first, keep the old one until its grants expire, then remove it.

new GrantKeys(keys, options?): GrantKeys;

Defined in: src/grants.ts:130

Parameter Type
keys readonly Uint8Array<ArrayBufferLike>[]
options GrantKeysOptions

GrantKeys

Error No key, a key that is not 32 bytes, duplicate keys, or a non-positive lifetime. A worker refuses to start rather than run with a key it misread.

readonly audience: string;

Defined in: src/grants.ts:120

See GrantKeysOptions.audience.


readonly clockSkewSeconds: number;

Defined in: src/grants.ts:124

See GrantKeysOptions.clockSkewSeconds.


readonly keys: readonly Uint8Array<ArrayBufferLike>[];

Defined in: src/grants.ts:118

32-byte keys, minting key first.


readonly maxTtlSeconds: number;

Defined in: src/grants.ts:122

See GrantKeysOptions.maxTtlSeconds.

aad(kid): Uint8Array;

Defined in: src/grants.ts:211

The AAD a token sealed under kid is bound to.

Parameter Type
kid Uint8Array

Uint8Array


keyIds(): Promise<Uint8Array<ArrayBufferLike>[]>;

Defined in: src/grants.ts:205

The key ids, in key order.

Promise<Uint8Array<ArrayBufferLike>[]>


static fromEnv(env?): GrantKeys | null;

Defined in: src/grants.ts:188

Read VGI_RPC_GRANT_KEYS (comma-separated, minting key first), VGI_RPC_GRANT_AUDIENCE and VGI_RPC_GRANT_MAX_TTL_SECONDS.

Parameter Type Description
env? Record<string, string | undefined> The environment; default process.env where it exists.

GrantKeys | null

The configuration, or null when no key is set – grants off.

Error A malformed key or lifetime.


static parse(encodedKeys, options?): GrantKeys;

Defined in: src/grants.ts:156

Build from standard base64 key text (padding optional), minting key first.

Parameter Type
encodedKeys Iterable<string>
options GrantKeysOptions

GrantKeys

Error A key that is not base64 of exactly 32 bytes.