Skip to content

MAX_TOKEN_BYTES

const MAX_TOKEN_BYTES: 4096 = 4096;

Defined in: src/token-identity.ts:95

Cap on a credential we will even attempt to resolve. Anything longer is not a bearer token; refusing early keeps a resolver from being handed megabytes.

Measured in UTF-8 bytes, which is the unit the purpose implies – what is bounded is what a resolver would have to handle, and megabytes are bytes. Spelled out because the ports reached for three different units: codepoints in Python and Rust, UTF-16 code units in Java, C# and (until now) TypeScript, bytes in Go and C++. All three agree for an ASCII credential, which every real bearer token is, so this bites only on a multibyte one – and "x".length counting UTF-16 units means this port was measuring a multibyte credential short. Bytes is also the most conservative of the three, so standardising on it can only refuse earlier.