auth-extensions.d.ts 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190
  1. /**
  2. * OAuth provider extensions for specialized authentication flows.
  3. *
  4. * This module provides ready-to-use OAuthClientProvider implementations
  5. * for common machine-to-machine authentication scenarios.
  6. */
  7. import { OAuthClientInformation, OAuthClientMetadata, OAuthTokens } from '../shared/auth.js';
  8. import { AddClientAuthentication, OAuthClientProvider } from './auth.js';
  9. /**
  10. * Helper to produce a private_key_jwt client authentication function.
  11. *
  12. * Usage:
  13. * const addClientAuth = createPrivateKeyJwtAuth({ issuer, subject, privateKey, alg, audience? });
  14. * // pass addClientAuth as provider.addClientAuthentication implementation
  15. */
  16. export declare function createPrivateKeyJwtAuth(options: {
  17. issuer: string;
  18. subject: string;
  19. privateKey: string | Uint8Array | Record<string, unknown>;
  20. alg: string;
  21. audience?: string | URL;
  22. lifetimeSeconds?: number;
  23. claims?: Record<string, unknown>;
  24. }): AddClientAuthentication;
  25. /**
  26. * Options for creating a ClientCredentialsProvider.
  27. */
  28. export interface ClientCredentialsProviderOptions {
  29. /**
  30. * The client_id for this OAuth client.
  31. */
  32. clientId: string;
  33. /**
  34. * The client_secret for client_secret_basic authentication.
  35. */
  36. clientSecret: string;
  37. /**
  38. * Optional client name for metadata.
  39. */
  40. clientName?: string;
  41. /**
  42. * Space-separated scopes values requested by the client.
  43. */
  44. scope?: string;
  45. }
  46. /**
  47. * OAuth provider for client_credentials grant with client_secret_basic authentication.
  48. *
  49. * This provider is designed for machine-to-machine authentication where
  50. * the client authenticates using a client_id and client_secret.
  51. *
  52. * @example
  53. * const provider = new ClientCredentialsProvider({
  54. * clientId: 'my-client',
  55. * clientSecret: 'my-secret'
  56. * });
  57. *
  58. * const transport = new StreamableHTTPClientTransport(serverUrl, {
  59. * authProvider: provider
  60. * });
  61. */
  62. export declare class ClientCredentialsProvider implements OAuthClientProvider {
  63. private _tokens?;
  64. private _clientInfo;
  65. private _clientMetadata;
  66. constructor(options: ClientCredentialsProviderOptions);
  67. get redirectUrl(): undefined;
  68. get clientMetadata(): OAuthClientMetadata;
  69. clientInformation(): OAuthClientInformation;
  70. saveClientInformation(info: OAuthClientInformation): void;
  71. tokens(): OAuthTokens | undefined;
  72. saveTokens(tokens: OAuthTokens): void;
  73. redirectToAuthorization(): void;
  74. saveCodeVerifier(): void;
  75. codeVerifier(): string;
  76. prepareTokenRequest(scope?: string): URLSearchParams;
  77. }
  78. /**
  79. * Options for creating a PrivateKeyJwtProvider.
  80. */
  81. export interface PrivateKeyJwtProviderOptions {
  82. /**
  83. * The client_id for this OAuth client.
  84. */
  85. clientId: string;
  86. /**
  87. * The private key for signing JWT assertions.
  88. * Can be a PEM string, Uint8Array, or JWK object.
  89. */
  90. privateKey: string | Uint8Array | Record<string, unknown>;
  91. /**
  92. * The algorithm to use for signing (e.g., 'RS256', 'ES256').
  93. */
  94. algorithm: string;
  95. /**
  96. * Optional client name for metadata.
  97. */
  98. clientName?: string;
  99. /**
  100. * Optional JWT lifetime in seconds (default: 300).
  101. */
  102. jwtLifetimeSeconds?: number;
  103. /**
  104. * Space-separated scopes values requested by the client.
  105. */
  106. scope?: string;
  107. }
  108. /**
  109. * OAuth provider for client_credentials grant with private_key_jwt authentication.
  110. *
  111. * This provider is designed for machine-to-machine authentication where
  112. * the client authenticates using a signed JWT assertion (RFC 7523 Section 2.2).
  113. *
  114. * @example
  115. * const provider = new PrivateKeyJwtProvider({
  116. * clientId: 'my-client',
  117. * privateKey: pemEncodedPrivateKey,
  118. * algorithm: 'RS256'
  119. * });
  120. *
  121. * const transport = new StreamableHTTPClientTransport(serverUrl, {
  122. * authProvider: provider
  123. * });
  124. */
  125. export declare class PrivateKeyJwtProvider implements OAuthClientProvider {
  126. private _tokens?;
  127. private _clientInfo;
  128. private _clientMetadata;
  129. addClientAuthentication: AddClientAuthentication;
  130. constructor(options: PrivateKeyJwtProviderOptions);
  131. get redirectUrl(): undefined;
  132. get clientMetadata(): OAuthClientMetadata;
  133. clientInformation(): OAuthClientInformation;
  134. saveClientInformation(info: OAuthClientInformation): void;
  135. tokens(): OAuthTokens | undefined;
  136. saveTokens(tokens: OAuthTokens): void;
  137. redirectToAuthorization(): void;
  138. saveCodeVerifier(): void;
  139. codeVerifier(): string;
  140. prepareTokenRequest(scope?: string): URLSearchParams;
  141. }
  142. /**
  143. * Options for creating a StaticPrivateKeyJwtProvider.
  144. */
  145. export interface StaticPrivateKeyJwtProviderOptions {
  146. /**
  147. * The client_id for this OAuth client.
  148. */
  149. clientId: string;
  150. /**
  151. * A pre-built JWT client assertion to use for authentication.
  152. *
  153. * This token should already contain the appropriate claims
  154. * (iss, sub, aud, exp, etc.) and be signed by the client's key.
  155. */
  156. jwtBearerAssertion: string;
  157. /**
  158. * Optional client name for metadata.
  159. */
  160. clientName?: string;
  161. /**
  162. * Space-separated scopes values requested by the client.
  163. */
  164. scope?: string;
  165. }
  166. /**
  167. * OAuth provider for client_credentials grant with a static private_key_jwt assertion.
  168. *
  169. * This provider mirrors {@link PrivateKeyJwtProvider} but instead of constructing and
  170. * signing a JWT on each request, it accepts a pre-built JWT assertion string and
  171. * uses it directly for authentication.
  172. */
  173. export declare class StaticPrivateKeyJwtProvider implements OAuthClientProvider {
  174. private _tokens?;
  175. private _clientInfo;
  176. private _clientMetadata;
  177. addClientAuthentication: AddClientAuthentication;
  178. constructor(options: StaticPrivateKeyJwtProviderOptions);
  179. get redirectUrl(): undefined;
  180. get clientMetadata(): OAuthClientMetadata;
  181. clientInformation(): OAuthClientInformation;
  182. saveClientInformation(info: OAuthClientInformation): void;
  183. tokens(): OAuthTokens | undefined;
  184. saveTokens(tokens: OAuthTokens): void;
  185. redirectToAuthorization(): void;
  186. saveCodeVerifier(): void;
  187. codeVerifier(): string;
  188. prepareTokenRequest(scope?: string): URLSearchParams;
  189. }
  190. //# sourceMappingURL=auth-extensions.d.ts.map