AUTH4D-25 TypeScript server token verification SDK
@auth4/sdk-server verifies tenant access tokens for Node services, Cloudflare Workers, and Hono
applications. Configure a tenant ID, its exact {AUTH_ORIGIN}/t/{tenantId} issuer, and the resource
audience expected by the protected API. The SDK accepts RS256 access tokens only and checks the
issuer, audience, configured tenant, expiration, required access-token claims, and the shared
AccessTokenClaimsSchema. ID tokens and the reserved management audience are rejected.
The SDK derives /.well-known/jwks.json from the configured issuer. It does not read issuer, jku,
or x5u URLs from an unverified JWT. JWKS responses have key-count and byte limits, redirects are
rejected, fetches time out, cached keys expire, concurrent refreshes are coalesced, and an unknown
key can trigger a bounded refresh for key rotation. Verification fails closed when fresh keys cannot
be obtained.
The framework-neutral parseBearerToken and authenticateRequest helpers work with web Request
objects. honoBearerAuth(client) sets verified claims in the Hono variable auth4Auth and returns
401 for missing or invalid bearer credentials. Node and Worker examples live in examples/server/.
Offline verification checks the signature and token lifetime; it does not query current session or user state. Revocation after issuance can therefore remain unobserved until the access token expires (up to the five-minute token lifetime). Use the online tenant UserInfo endpoint when current session or user state is required; that check adds network latency and an Auth4 service dependency.
Source: docs/api-spec/auth4d-25.md