Skip to content

TokenIdentity

Defined in: src/token-identity.ts:458

The identity an opaque credential authenticates as.

Never carries claims. A pass-through claims field would let a worker choose its caller’s tenant routing, its row scope, and its policy branch, and the asker derives everything it needs from the principal alone.

principal: string;

Defined in: src/token-identity.ts:462

The canonical principal, in the exact form the worker itself would derive – so an asker that normalises differently does not authorize as one identity while the worker serves another.


optional tokenName?: string;

Defined in: src/token-identity.ts:465

Human-readable name for the credential, for audit trails. Never the credential. Defaults to "" on the wire.


optional ttlSeconds?: number;

Defined in: src/token-identity.ts:470

How long the answer may be cached. The caller does the caching. Treat it as an authorization window: for any path the asker serves without re-presenting the credential it is exactly that, and therefore also the revocation lag. Defaults to DEFAULT_IDENTITY_TTL_SECONDS.