Signing people in
The OAuth client that connects a person to the app, where connections are stored, and how a refused refresh is read.
Exports of @crouter/sdk, read from the TypeScript compiler at build time. Types re-exported from @crouter/api are documented with that package.
AuthorizeNonce
type declared in oauth/index.ts
authorizeUrl's nonce: string when the scopes are known to include openid, undefined when known not to, else either.
string extends S[number] ? string | undefined : "openid" extends S[number] ? string : undefinedConnection
interface declared in oauth/index.ts
Prop
Type
ConnectionStore
interface declared in oauth/index.ts
Prop
Type
generateKeyPair
function declared in oauth/keygen.ts
Make an app signing key and the public JWK to register in the directory.
() => Promise<{ privateJwk: JWK; publicJwk: JWK; kid: string; }>Identity
interface declared in oauth/index.ts
A person's crouter cloud identity from a sign-in-only (openid, openid email, openid profile, or openid email profile) request, read from an
ID token the SDK verified: ES256 signature against the directory's JWKS, iss, aud = the client id,
exp, and the nonce from authorizeUrl. It is not a connection: it holds no runtime URL, refresh
token, or grant, and nothing can be called on the person's runtime with it.
Prop
Type
MemoryConnectionStore
class declared in oauth/index.ts
Prop
Type
OAuth2Client
class declared in oauth/index.ts
Prop
Type
OAuth2Options
interface declared in oauth/index.ts
Prop
Type
parsePrivateJwk
function declared in oauth/keygen.ts
Check that value (a JWK object or its JSON text) is a private signing key with a kid, and return it as
OAuth2Options.privateKey takes it. source names where it came from in the error, e.g. a file path.
(value: string | JWK, source?: string) => JWK & { d: string; kid: string; }privateKeyFromFile
function declared in oauth/keygen.ts
Read a private JWK file, such as the one crouter-sdk keygen writes, and check it as parsePrivateJwk does. Node only.
(path: string) => Promise<JWK & { d: string; kid: string; }>profileFromClaims
function declared in oauth/index.ts
The profile claims a verified ID token carries, each only when present: use it on Connection.idToken after verifyIdToken for a sign-in that requested runtime scopes (exchangeCode), as exchangeIdentity does for a sign-in-only one.
(claims: IdTokenClaims) => Pick<Identity, 'name' | 'givenName' | 'familyName' | 'picture'>RefreshFailure
interface declared in oauth/index.ts
One connection refreshIdleConnections could not refresh. reason is refreshRefusal(error).
Prop
Type
refreshRefusal
function declared in oauth/index.ts
What a refused refresh means (RefreshRefusal), or null when error is not the directory refusing one.
Takes any error a connected client or refresh threw; only APIError with origin: 'directory' counts.
(error: unknown) => RefreshRefusal | nullRefreshRefusal
type declared in oauth/index.ts
Why the directory refused a connection's refresh token, and what it means for the app's data:
- removed (grant_removed): the person removed the app or deleted their account. The runtime has
deleted the app's runs; delete what the app stores for them.
- paused (grant_suspended): the grant is suspended or expired. Nothing was deleted; keep the
person's data and show the app paused until they sign in again.
- reconnect (refresh_token_expired, refresh_token_reused, or grant_revoked with no reason given):
the grant still exists. Nothing was deleted; drop the dead connection and ask them to sign in again.
"paused" | "reconnect" | "removed"