Sign in

Class: MonoCloudOidcBackendClient

Constructor

new MonoCloudOidcBackendClient(tenantDomain: string, audience: string, options?: MonoCloudOidcBackendClientOptions): MonoCloudOidcBackendClient

Creates a new instance of MonoCloudOidcBackendClient.

Parameters

ParameterTypeDescription
tenantDomainstringThe tenant domain URL.
audiencestringThe expected audience value used to validate the aud claim in access tokens.
options?MonoCloudOidcBackendClientOptionsAdditional client configuration options.

decodeJwt()

static decodeJwt(jwt: string): JwtClaims

Decodes the payload of a JSON Web Token (JWT) and returns it as an object.

Note: THIS METHOD DOES NOT VERIFY JWT TOKENS.

Parameters

ParameterTypeDescription
jwtstringJWT to decode.

Returns

JwtClaims

Decoded payload.

Throws

MonoCloudTokenError - If decoding fails

getJwks()

getJwks(forceRefresh?: boolean): Promise<Jwks>

Fetches the JSON Web Keys used to sign the ID token. The JWKS is cached for 5 minutes by default.

Parameters

ParameterTypeDescription
forceRefreshbooleanIf true, bypasses the cache and fetches fresh set of JWKS from the server.

Returns

Promise<Jwks>

The JSON Web Key Set containing the public keys for token verification.

Throws

MonoCloudHttpError - Thrown if there is a network error during the request or unexpected status code during the request or a serialization error while processing the response.

getMetadata()

getMetadata(forceRefresh?: boolean): Promise<IssuerMetadata>

Fetches the authorization server metadata from the .well-known endpoint. The metadata is cached for 5 minutes by default.

Parameters

ParameterTypeDescription
forceRefreshbooleanIf true, bypasses the cache and fetches fresh metadata from the server.

Returns

Promise<IssuerMetadata>

The issuer metadata for the tenant, retrieved from the OpenID Connect discovery endpoint.

Throws

MonoCloudHttpError - Thrown if there is a network error during the request or unexpected status code during the request or a serialization error while processing the response.

introspectAccessToken()

introspectAccessToken(accessToken: string, options?: IntrospectOptions): Promise<AccessTokenClaims>

Validates an opaque access token using the OAuth 2.0 Token Introspection endpoint (RFC 7662).

Parameters

ParameterTypeDescription
accessTokenstringThe access token string to introspect.
options?IntrospectOptionsClaims validation options.

Returns

Promise<AccessTokenClaims>

Validated access token claims (without the active field).

Throws

MonoCloudTokenError - If the token is not active or claim validation fails.

Throws

MonoCloudOPError - When the introspection endpoint returns a standardized OAuth 2.0 error response.

Throws

MonoCloudHttpError - Thrown if there is a network error during the request or unexpected status code during the request or a serialization error while processing the response.

Throws

MonoCloudValidationError - When the access token is empty or the introspection endpoint is not available in the issuer metadata or claims validation fails.


setClockSkew()

setClockSkew(clockSkew: number): void

Sets clock skew used for access token time-based claim validation.

Parameters

ParameterTypeDescription
clockSkewnumberNumber of seconds to adjust the current time to account for clock differences.

Returns

void


setClockTolerance()

setClockTolerance(clockTolerance: number): void

Sets clock tolerance used for access token time-based claim validation.

Parameters

ParameterTypeDescription
clockTolerancenumberAdditional time tolerance in seconds for time-based claim validation.

Returns

void


validateJwtAccessToken()

validateJwtAccessToken(accessToken: string, options?: ValidateJwtAccessTokenOptions): Promise<AccessTokenClaims>

Validates a JWT access token by verifying the signature and claims.

Parameters

ParameterTypeDescription
accessTokenstringThe access token JWT string to validate.
options?ValidateJwtAccessTokenOptionsValidation options.

Returns

Promise<AccessTokenClaims>

Validated access token claims.

Throws

MonoCloudTokenError - If JWT parsing, signature verification, or claim validation fails.

Throws

MonoCloudHttpError - Thrown if there is a network error during the request or unexpected status code during the request or a serialization error while processing the response.

Throws

MonoCloudValidationError - When the access token is empty or claims validation fails.

© 2024 MonoCloud. All rights reserved.