Skip to content

checkFreshness

function checkFreshness(
auth,
maxAuthAge,
now?
): number;

Defined in: src/token-identity.ts:425

Return the caller’s auth_time, or refuse if it is missing or stale.

A credential with no verifiable auth_time cannot mint. That single rule is what stops a grant being used to mint another grant: a grant is not an IdP-issued token, so it carries no auth_time, so the lineage cannot escape the identity provider. It also makes subprocess and unix transports fail closed for free – there is no authenticated principal there at all.

A static bearer proves a machine holds a secret, never that a human just authenticated, so it is refused here too.

Warning: auth_time is an OIDC claim meaning when this session began, which can be arbitrarily old while still present and cryptographically valid. Requiring it is not the same as requiring a recent login: the deployment must send max_age (or an appropriate acr) at the authorize endpoint for this guard to mean what it says.

maxAuthAge and now are seconds, matching the claim’s own units.

Parameter Type
auth AuthContext
maxAuthAge number
now? number

number