Skip to content

IdentityOptions

Defined in: src/token-identity.ts:568

How a deployment configures IdentityImpl.

optional grantKeys?: GrantKeys;

Defined in: src/token-identity.ts:586

Sealed-grant configuration (WIRE_PROTOCOL.md §16). When given and mintGrant is not, the framework mints sealed grants itself; an HTTP handler serving this identity also accepts them back as bearer credentials. Absent changes nothing.


optional introspectPrincipals?: Iterable<string, any, any>;

Defined in: src/token-identity.ts:578

Who may call introspect_token. Required whenever resolveToken is supplied; there is no permissive default. The allowlist is the control: introspection is not rate limited (see the module comment).


optional maxAuthAge?: number;

Defined in: src/token-identity.ts:581

How recently a caller must have authenticated to mint a grant, in seconds.


optional mintGrant?: GrantMinter;

Defined in: src/token-identity.ts:574

(principal, purpose, scopes, ttlSeconds) -> IssuedGrant.


optional resolveToken?: TokenResolver;

Defined in: src/token-identity.ts:572

(token) -> TokenIdentity | null. null means the store answered and the credential is unknown; throw IdentityUnavailableError for “not knowable”.