Skip to content

IdentityImpl

Defined in: src/token-identity.ts:607

Applies this module’s guards, then delegates to worker-supplied hooks.

The framework owns the guards and owns none of the policy. It decides who may ask and what shape of credential is refused outright; the worker decides what a credential resolves to and whether a grant is minted. That split is deliberate – the guards are the part that is identical in every deployment and catastrophic to get wrong, and the policy is the part that is different in every deployment and cannot be guessed.

A method whose hook is absent is not registered at all, so the protocol a server hosts describes what it actually does. A worker that resolves credentials but does not mint grants hosts introspect_token and not issue_grant, and a client discovers that through ordinary reflection rather than by calling and reading an error. Absent beats routed-and-refusing: it is what keeps a dependency upgrade from growing a credential-to-identity oracle on every existing worker.

new IdentityImpl(options?): IdentityImpl;

Defined in: src/token-identity.ts:614

Parameter Type
options IdentityOptions

IdentityImpl

get grantKeys(): GrantKeys | undefined;

Defined in: src/token-identity.ts:626

The sealed-grant configuration, when this deployment has one.

GrantKeys | undefined


get resolveToken():
| TokenResolver
| undefined;

Defined in: src/token-identity.ts:632

The worker’s resolveToken, which an HTTP handler also consults for bearer credentials (WIRE_PROTOCOL.md §16).

| TokenResolver | undefined

introspectToken(token, auth): Promise<TokenIdentity>;

Defined in: src/token-identity.ts:658

Resolve token, after checking the caller may ask.

The guard order is load-bearing and must not be tidied: authorization comes before anything looks at the subject credential – including its length and its shape – so an unauthorized caller learns nothing about it, not even how long looking at it took.

Parameter Type
token string
auth AuthContext

Promise<TokenIdentity>


issueGrant(
purpose,
scopes,
ttlSeconds,
auth
): Promise<IssuedGrant>;

Defined in: src/token-identity.ts:686

Mint a grant for the caller, after checking they authenticated recently.

Parameter Type
purpose string
scopes readonly string[]
ttlSeconds number
auth AuthContext

Promise<IssuedGrant>


offeredMethods(): ReadonlySet<string>;

Defined in: src/token-identity.ts:643

Return the methods this deployment can actually answer.

A method whose hook is absent is not registered, so the protocol a server hosts describes what it does – and a client learns that from reflection rather than by calling and reading an error.

ReadonlySet<string>