IssuedGrant
Defined in: src/token-identity.ts:481
A standing delegation credential.
OAuth cannot express durable delegation: it fuses the grant, the credential and the session into one refresh token, so an IdP shortening session lifetime shortens the grant. This is the durable record – minted while the user is present, presented later by unattended automation as an ordinary bearer.
Properties
Section titled “Properties”expiresAt
Section titled “expiresAt”expiresAt: number;Defined in: src/token-identity.ts:491
Unix timestamp after which the worker will stop honouring the grant. Required because the framework cannot enforce it: the real lifetime lives inside the opaque token, so this is a declaration rather than an enforcement. A worker that must state a lifetime has thought about one.
grantId?
Section titled “grantId?”optional grantId?: string;Defined in: src/token-identity.ts:494
Correlation handle for the audit trail. Not a credential and not secret – it is what ties a mint record to later use.
token: string;Defined in: src/token-identity.ts:486
The credential. Opaque to the framework – the worker owns the format entirely (a sealed envelope, a database row, or a credential brokered from the IdP are all equally valid and equally invisible here). Never parsed, never logged.
