Configuration options used to initialize the MonoCloudOidcBackendClient.
| Property | Type | Description |
|---|---|---|
clientAuthMethod? | ClientAuthMethod | Client authentication method used when the client authenticates to the authorization server. |
clientId? | string | Client identifier of the application registered in MonoCloud. |
clientSecret? | string | Jwk | Client secret or key material used for client authentication. When clientAuthMethod is client_secret_jwt and a plain-text secret is provided, the default signing algorithm is HS256. To use a different algorithm, provide a symmetric JSON Web Key (JWK) (kty: "oct") with the desired algorithm specified in its alg property. When clientAuthMethod is spiffe_jwt, provide the SPIFFE JWT-SVID (obtained from the SPIFFE Workload API) as the plain-text string; it is sent as the client_assertion. |
clockSkew? | number | Number of seconds to adjust the current time to account for clock differences. |
clockTolerance? | number | Additional time tolerance in seconds for time-based claim validation. |
fetcher? | {(input: URL | RequestInfo, init?: RequestInit): Promise<Response>; (input: string | URL | Request, init?: RequestInit): Promise<Response>; } | Optional custom fetch implementation used for network requests. |
groupOptions? | IsUserInGroupOptions | Options for group membership validation applied to all token validations performed by this client. |
jwksCacheDuration? | number | Duration (in seconds) to cache the JSON Web Key Set (JWKS) retrieved from the authorization server. |
jwksResolver? | () => Jwks | Promise<Jwks> | Optional custom resolver for the JSON Web Key Set (JWKS). |
metadataCacheDuration? | number | Duration (in seconds) to cache OpenID Connect discovery metadata. |
metadataResolver? | () => IssuerMetadata | Promise<IssuerMetadata> | Optional custom resolver for the issuer metadata (OpenID Connect discovery document). |
trustStoreId? | string | Identifier of the trust store whose mTLS endpoint aliases should be used when authenticating with a mutual-TLS client authentication method. |