Skip to content

VerifyStreamTokenOptions

Defined in: packages/server/src/circuits/stream-token.ts:164

Verify a token and read its grants back.

now is the request-start time, and is passed rather than read here so that a long-poll held open across the expiry is judged by when it started — the alternative silently kills connections mid-flight at the TTL boundary, which presents as a stall rather than as the re-auth it is.

Signature verification goes through crypto.subtle.verify, so the comparison is the platform’s constant-time one rather than a string equality that leaks by how early it diverges.

optional allowExpired?: boolean

Defined in: packages/server/src/circuits/stream-token.ts:174

Accept a token past its expiry, for the re-mint path only.

The signature is still verified, so the grants are still ones this control plane issued — that is the whole claim being relied on. Expiry bounds how long a grant keeps working, and the re-mint re-authorizes every grant before re-signing — the shared tier against the live entitlement set, the private tier by recompiling its shape against the subject’s current claims — so an expired token buys its bearer nothing on its own. Never set this on a read.