TokenExchange

org.llm4s.llmconnect.auth.TokenExchange
@Experimental
object TokenExchange

The RFC 8693 token exchange and its caching provider.

Attributes

Graph
Supertypes
class Object
trait Matchable
class Any
Self type

Members list

Value members

Concrete methods

def provider(config: TokenExchangeConfig, httpClient: Llm4sHttpClient, refreshMargin: FiniteDuration): AccessTokenProvider
def rfc8693(config: TokenExchangeConfig, httpClient: Llm4sHttpClient, clock: Clock, timeout: FiniteDuration): () => Result[AccessToken]

One exchange per call: read the identity token, post it, parse the reply.

One exchange per call: read the identity token, post it, parse the reply.

Attributes

Concrete fields

val DefaultLifetime: FiniteDuration

The lifetime assumed for a token whose reply has no expires_in (RFC 6749 makes it optional) and which is not a JWT carrying an exp claim: short, so a token that in fact lives less is not used for long after it has expired - and a 401 refreshes it in any case.

The lifetime assumed for a token whose reply has no expires_in (RFC 6749 makes it optional) and which is not a JWT carrying an exp claim: short, so a token that in fact lives less is not used for long after it has expired - and a 401 refreshes it in any case.

Attributes

val DefaultTimeout: FiniteDuration
val MaxLifetime: FiniteDuration

The longest lifetime a token is believed to have, whatever the endpoint's expires_in says: a reply claiming more (1e30, say) is clamped to this, so a buggy or hostile endpoint cannot make a token outlive any sensible rotation or overflow the arithmetic.

The longest lifetime a token is believed to have, whatever the endpoint's expires_in says: a reply claiming more (1e30, say) is clamped to this, so a buggy or hostile endpoint cannot make a token outlive any sensible rotation or overflow the arithmetic.

Attributes