AUTH4D-24 TypeScript browser SDK
@auth4/sdk-browser accepts a tenant issuer, public clientId, and exact redirectUri. It
loads and validates tenant discovery, uses authorization code with S256 PKCE, and validates the
returned RS256 ID token signature, issuer, tenant, audience, nonce, and lifetime against the
tenant JWKS. It rejects implicit and password flows and never requests offline_access.
The SDK stores only short-lived state, nonce, and the PKCE verifier in sessionStorage. Discovery
and JWKS data follow server cache directives and are cached in memory for no more than five minutes.
Access tokens stay in memory for
their advertised lifetime, which is capped at the platform’s five-minute access-token lifetime.
getUser() calls the discovered UserInfo endpoint and checks that its subject matches the validated
ID token. logout() clears local token state and revokes the active access token using the
discovered revocation endpoint. The browser SDK does not expose refresh tokens or persistent token
storage.
The client throws Auth4BrowserError with a stable code for protocol, configuration, storage,
and cancellation failures. Operations that make requests accept AbortSignal. See
examples/browser/README.md for a bundled example.
Source: docs/api-spec/auth4d-24.md