IdentityOptions
Defined in: src/token-identity.ts:568
How a deployment configures IdentityImpl.
Properties
Section titled “Properties”grantKeys?
Section titled “grantKeys?”optional grantKeys?: GrantKeys;Defined in: src/token-identity.ts:586
Sealed-grant configuration (WIRE_PROTOCOL.md §16). When given and
mintGrant is not, the framework mints sealed grants itself; an HTTP
handler serving this identity also accepts them back as bearer
credentials. Absent changes nothing.
introspectPrincipals?
Section titled “introspectPrincipals?”optional introspectPrincipals?: Iterable<string, any, any>;Defined in: src/token-identity.ts:578
Who may call introspect_token. Required whenever resolveToken is
supplied; there is no permissive default. The allowlist is the control:
introspection is not rate limited (see the module comment).
maxAuthAge?
Section titled “maxAuthAge?”optional maxAuthAge?: number;Defined in: src/token-identity.ts:581
How recently a caller must have authenticated to mint a grant, in seconds.
mintGrant?
Section titled “mintGrant?”optional mintGrant?: GrantMinter;Defined in: src/token-identity.ts:574
(principal, purpose, scopes, ttlSeconds) -> IssuedGrant.
resolveToken?
Section titled “resolveToken?”optional resolveToken?: TokenResolver;Defined in: src/token-identity.ts:572
(token) -> TokenIdentity | null. null means the store answered and the
credential is unknown; throw IdentityUnavailableError for “not
knowable”.
