(
token: string,
jwks: JWTVerifyGetKey,
options: {
readonly issuer: string;
readonly audience: string;
},
)
| 97 | ); |
| 98 | |
| 99 | export const verifyMcpAccessToken = ( |
| 100 | token: string, |
| 101 | jwks: JWTVerifyGetKey, |
| 102 | options: { |
| 103 | readonly issuer: string; |
| 104 | readonly audience: string; |
| 105 | }, |
| 106 | ) => |
| 107 | Effect.gen(function* () { |
| 108 | const { payload } = yield* Effect.tryPromise({ |
| 109 | try: () => |
| 110 | jwtVerify(token, jwks, { |
| 111 | ...workosAccessTokenOptions, |
| 112 | issuer: options.issuer, |
| 113 | audience: options.audience, |
| 114 | }), |
| 115 | catch: classifyJwtVerificationError, |
| 116 | }).pipe(withJwtVerificationSpan); |
| 117 | |
| 118 | return identityFromClaims(payload); |
| 119 | }); |
| 120 | |
| 121 | export const verifyWorkOSMcpAccessToken = ( |
| 122 | token: string, |
no test coverage detected