org.llm4s.llmconnect.auth

Members list

Type members

Classlikes

@Experimental
final case class AccessToken(value: String, expiresAt: Instant)

A bearer token and when it stops being valid. The value is redacted in toString.

A bearer token and when it stops being valid. The value is redacted in toString.

Attributes

Supertypes
trait Serializable
trait Product
trait Equals
class Object
trait Matchable
class Any
Show all
@Experimental

Supplies the bearer token for each request, refreshing it as needed.

Supplies the bearer token for each request, refreshing it as needed.

Attributes

Supertypes
class Object
trait Matchable
class Any
Known subtypes
@Experimental
final case class AuthConfig

A named provider section's auth block: the workload's identity token, plus the keys the provider declares in ProviderConfigSpec.authExtras (a token URL, a federation rule id, ...), resolved by validation. Values are redacted in toString.

A named provider section's auth block: the workload's identity token, plus the keys the provider declares in ProviderConfigSpec.authExtras (a token URL, a federation rule id, ...), resolved by validation. Values are redacted in toString.

Extras are trimmed and a blank one is dropped, however the config is built - as a section's auth block is read - so a blank clientId is absent rather than posted empty, and a required key left blank is reported as missing.

Attributes

Companion
object
Supertypes
trait Serializable
trait Product
trait Equals
class Object
trait Matchable
class Any
Show all
@Experimental
object AuthConfig

Attributes

Companion
class
Supertypes
trait Product
trait Mirror
class Object
trait Matchable
class Any
Self type
AuthConfig.type
@Experimental
final class CachingAccessTokenProvider(fetch: () => Result[AccessToken], refreshMargin: FiniteDuration, clock: Clock) extends AccessTokenProvider

Caches the token fetch returns until refreshMargin before it expires - or half-way through its life, if it lives shorter than twice the margin. Concurrent callers share one in-flight fetch.

Caches the token fetch returns until refreshMargin before it expires - or half-way through its life, if it lives shorter than twice the margin. Concurrent callers share one in-flight fetch.

A failed fetch is shared for a brief window: the callers waiting behind it get the same failure at once instead of each making their own attempt in turn, which during an outage would hold the last of N callers for N times the exchange's timeout. A rejection (an authentication or configuration error, or any other error not marked recoverable) is shared for FailureTtl (5 seconds); a transient failure (a org.llm4s.error.RecoverableError: network, timeout, rate limit, 5xx) for TransientFailureTtl (1 second) - long enough for the callers queued behind the fetch, short enough that a blip does not outlive itself. After the window the next call tries again; a success, or a rejected cached token, ends it sooner.

A cancellation is never shared. A fetch whose thread is interrupted - it returns CancelledError, throws InterruptedException, or fails while the flag is set - returns CancelledError to that caller alone, with its interrupt flag set, and caches nothing: the next caller through the lock makes its own fetch.

Attributes

Companion
object
Supertypes
class Object
trait Matchable
class Any
@Experimental

Attributes

Companion
class
Supertypes
class Object
trait Matchable
class Any
Self type
@Experimental

Where a workload's identity token comes from - typically a SPIFFE JWT-SVID file that spiffe-helper keeps fresh. The configured form, before it is read.

Where a workload's identity token comes from - typically a SPIFFE JWT-SVID file that spiffe-helper keeps fresh. The configured form, before it is read.

Attributes

Supertypes
trait Enum
trait Serializable
trait Product
trait Equals
class Object
trait Matchable
class Any
Show all
@Experimental

Fetches the subject token a token exchange presents.

Fetches the subject token a token exchange presents.

Attributes

Companion
object
Supertypes
class Object
trait Matchable
class Any
@Experimental

Attributes

Companion
trait
Supertypes
class Object
trait Matchable
class Any
Self type
@Experimental
object TokenExchange

The RFC 8693 token exchange and its caching provider.

The RFC 8693 token exchange and its caching provider.

Attributes

Supertypes
class Object
trait Matchable
class Any
Self type
@Experimental
final case class TokenExchangeConfig

An RFC 8693 token exchange: present identityToken at tokenUrl, get back a short-lived bearer token. Databricks workload identity federation is one such endpoint (https://<workspace>/oidc/v1/token, scope = all-apis, clientId = the service principal).

An RFC 8693 token exchange: present identityToken at tokenUrl, get back a short-lived bearer token. Databricks workload identity federation is one such endpoint (https://<workspace>/oidc/v1/token, scope = all-apis, clientId = the service principal).

toString shows tokenUrl without its userinfo or query, which may carry credentials, and redacts clientId.

Attributes

Companion
object
Supertypes
trait Serializable
trait Product
trait Equals
class Object
trait Matchable
class Any
Show all
@Experimental

Attributes

Companion
class
Supertypes
trait Product
trait Mirror
class Object
trait Matchable
class Any
Self type