Skip to content

IssuedGrant

Defined in: src/token-identity.ts:481

A standing delegation credential.

OAuth cannot express durable delegation: it fuses the grant, the credential and the session into one refresh token, so an IdP shortening session lifetime shortens the grant. This is the durable record – minted while the user is present, presented later by unattended automation as an ordinary bearer.

expiresAt: number;

Defined in: src/token-identity.ts:491

Unix timestamp after which the worker will stop honouring the grant. Required because the framework cannot enforce it: the real lifetime lives inside the opaque token, so this is a declaration rather than an enforcement. A worker that must state a lifetime has thought about one.


optional grantId?: string;

Defined in: src/token-identity.ts:494

Correlation handle for the audit trail. Not a credential and not secret – it is what ties a mint record to later use.


token: string;

Defined in: src/token-identity.ts:486

The credential. Opaque to the framework – the worker owns the format entirely (a sealed envelope, a database row, or a credential brokered from the IdP are all equally valid and equally invisible here). Never parsed, never logged.