Skip to content

TokenScope

Defined in: src/http/token.ts:32

Everything the AEAD associated data of a state or call token is bound to.

Passed as one object rather than four positional strings because every field is a string and a transposition would still compile – and a token bound to the wrong scope fails open in the only direction that matters: it opens.

optional domain?: string | null;

Defined in: src/http/token.ts:52

Authentication domain of the issuing principal.


optional evidenceBinding?: string;

Defined in: src/http/token.ts:50

Digest of the resolved transport-peer evidence, when there is any. Its presence selects the bound AAD prefix.


principal: string | null | undefined;

Defined in: src/http/token.ts:47

The issuing principal; null for an anonymous caller. An authenticator that deliberately uses an empty principal is still authenticated, and the empty string and null produce different AAD.


protocol: string;

Defined in: src/http/token.ts:43

Wire name of the protocol that owns the stream, or SERVER_SCOPE.

Bound into the AAD rather than carried in the plaintext so a cross-protocol continuation fails the AEAD tag check – rejected exactly as an invalid token, with no comparison code to get wrong and nothing to forget on the call-state cache-hit path, where the call token is never opened at all. The cursor is always opened first, so binding it here covers both paths.