TokenIdentity
Defined in: src/token-identity.ts:458
The identity an opaque credential authenticates as.
Never carries claims. A pass-through claims field would let a worker choose its caller’s tenant routing, its row scope, and its policy branch, and the asker derives everything it needs from the principal alone.
Properties
Section titled “Properties”principal
Section titled “principal”principal: string;Defined in: src/token-identity.ts:462
The canonical principal, in the exact form the worker itself would derive – so an asker that normalises differently does not authorize as one identity while the worker serves another.
tokenName?
Section titled “tokenName?”optional tokenName?: string;Defined in: src/token-identity.ts:465
Human-readable name for the credential, for audit trails. Never the
credential. Defaults to "" on the wire.
ttlSeconds?
Section titled “ttlSeconds?”optional ttlSeconds?: number;Defined in: src/token-identity.ts:470
How long the answer may be cached. The caller does the caching. Treat it as an authorization window: for any path the asker serves without re-presenting the credential it is exactly that, and therefore also the revocation lag. Defaults to DEFAULT_IDENTITY_TTL_SECONDS.
