TokenVerifier that turns a bearer token into a verified AccessToken. Pass one via the auth option and every HTTP request is verified before it reaches your handlers:
This page is under construction. The outline below sketches what it will cover.
- The
TokenVerifiermodel — verify a bearer token, produce anAccessToken(subject, scopes, claims) available to handlers viagetContext().auth. - Where auth applies — HTTP transport request verification; interaction with middleware and mounted children.
- Choosing a strategy — JWT, introspection, or static tokens for verification; a full OAuth provider or proxy when you need the authorization flow; scopes and per-component checks for fine-grained access.