Skip to content

verifyGrantToken

function verifyGrantToken(
keys,
token,
now?
): Promise<GrantClaims>;

Defined in: src/grants.ts:379

Verify a sealed grant and return its claims.

Order, normative: prefix, length, canonical base64url, key id, AEAD open, payload, then lifetime – the lifetime is inside the ciphertext, so it is only trusted after the tag verified.

Parameter Type Description
keys GrantKeys -
token string -
now? number Override the clock (seconds), for tests.

Promise<GrantClaims>

GrantInvalidError For every cause; expired only for an authentic grant outside its lifetime.