(
token: string,
jwks: JWTVerifyGetKey,
options: {
readonly issuer: string;
readonly audience: string;
},
)
| 119 | }); |
| 120 | |
| 121 | export const verifyWorkOSMcpAccessToken = ( |
| 122 | token: string, |
| 123 | jwks: JWTVerifyGetKey, |
| 124 | options: { |
| 125 | readonly issuer: string; |
| 126 | readonly audience: string; |
| 127 | }, |
| 128 | ) => |
| 129 | Effect.gen(function* () { |
| 130 | const verified = yield* verifyMcpAccessToken(token, jwks, { |
| 131 | issuer: options.issuer, |
| 132 | audience: options.audience, |
| 133 | }); |
| 134 | yield* Effect.annotateCurrentSpan({ |
| 135 | "mcp.auth.audience_mode": "workos_client", |
| 136 | }); |
| 137 | return verified; |
| 138 | }); |
| 139 | |
| 140 | // Verify a WorkOS user_management access token (the CLI `executor login` device |
| 141 | // flow). Unlike the MCP /oauth2 tokens, these are signed by the SSO keyset |
no test coverage detected