VerifyStreamTokenOptions
Defined in: packages/server/src/circuits/stream-token.ts:164
Verify a token and read its grants back.
now is the request-start time, and is passed rather than read here so that a long-poll held open
across the expiry is judged by when it started — the alternative silently kills connections
mid-flight at the TTL boundary, which presents as a stall rather than as the re-auth it is.
Signature verification goes through crypto.subtle.verify, so the comparison is the platform’s
constant-time one rather than a string equality that leaks by how early it diverges.
Properties
Section titled “Properties”allowExpired?
Section titled “allowExpired?”
optionalallowExpired?:boolean
Defined in: packages/server/src/circuits/stream-token.ts:174
Accept a token past its expiry, for the re-mint path only.
The signature is still verified, so the grants are still ones this control plane issued — that is the whole claim being relied on. Expiry bounds how long a grant keeps working, and the re-mint re-authorizes every grant before re-signing — the shared tier against the live entitlement set, the private tier by recompiling its shape against the subject’s current claims — so an expired token buys its bearer nothing on its own. Never set this on a read.