AUTH4D-25 TypeScript server token verification SDK

@auth4/sdk-server verifies tenant access tokens for Node services, Cloudflare Workers, and Hono applications. Configure a tenant ID, its exact {AUTH_ORIGIN}/t/{tenantId} issuer, and the resource audience expected by the protected API. The SDK accepts RS256 access tokens only and checks the issuer, audience, configured tenant, expiration, required access-token claims, and the shared AccessTokenClaimsSchema. ID tokens and the reserved management audience are rejected.

The SDK derives /.well-known/jwks.json from the configured issuer. It does not read issuer, jku, or x5u URLs from an unverified JWT. JWKS responses have key-count and byte limits, redirects are rejected, fetches time out, cached keys expire, concurrent refreshes are coalesced, and an unknown key can trigger a bounded refresh for key rotation. Verification fails closed when fresh keys cannot be obtained.

The framework-neutral parseBearerToken and authenticateRequest helpers work with web Request objects. honoBearerAuth(client) sets verified claims in the Hono variable auth4Auth and returns 401 for missing or invalid bearer credentials. Node and Worker examples live in examples/server/.

Offline verification checks the signature and token lifetime; it does not query current session or user state. Revocation after issuance can therefore remain unobserved until the access token expires (up to the five-minute token lifetime). Use the online tenant UserInfo endpoint when current session or user state is required; that check adds network latency and an Auth4 service dependency.

Source: docs/api-spec/auth4d-25.md