A local identity provider plus a protected API, for testing workload-identity auth without a network: an RFC 8693 token endpoint (Databricks' /oidc/v1/token), Anthropic's jwt-bearer grant, and OpenAI-format and Anthropic-format endpoints (each streaming when the request asks) that accept only the most recently issued token. Tokens are t1, t2, ... in issue order.
Attributes
- Companion
- object
- Graph
-
- Supertypes
-
class Objecttrait Matchableclass Any
Members list
Value members
Concrete methods
The Authorization header of every API call, in order.
The Authorization header of every API call, in order.
Attributes
Every token request received, as its form fields (or JSON fields, for the Anthropic grant).
Every token request received, as its form fields (or JSON fields, for the Anthropic grant).
Attributes
The tokens issued so far: t1, t2, ...
The tokens issued so far: t1, t2, ...
Attributes
Answers the next n API calls with 401, whatever token they carry.
Answers the next n API calls with 401, whatever token they carry.
Attributes
Answers the next n API calls with status (401, or 403 for a token that is valid but not allowed).
Answers the next n API calls with status (401, or 403 for a token that is valid but not allowed).
Attributes
How long the tokens issued from now on say they live; 3600 by default.
How long the tokens issued from now on say they live; 3600 by default.
Attributes
Decides whether a presented subject token is acceptable; the default accepts anything non-blank.
Decides whether a presented subject token is acceptable; the default accepts anything non-blank.
Attributes
Concrete fields
This server under a URL that llm4s's workload-identity rules refuse - plain http to a host that is not one of the loopback literals they accept (localhost, 127.x.y.z, [::1]) - but that still reaches it: the IPv4-mapped IPv6 form of 127.0.0.1, which the JVM connects to over IPv4. Configure a baseUrl or tokenUrl with it to prove a refusal happens before any request: a request that went out would show in exchanges or apiAuthorizations.
This server under a URL that llm4s's workload-identity rules refuse - plain http to a host that is not one of the loopback literals they accept (localhost, 127.x.y.z, [::1]) - but that still reaches it: the IPv4-mapped IPv6 form of 127.0.0.1, which the JVM connects to over IPv4. Configure a baseUrl or tokenUrl with it to prove a refusal happens before any request: a request that went out would show in exchanges or apiAuthorizations.