npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@mcp-abap-adt/interfaces-auth-broker

v1.3.0

Published

The broker's port: the destination (IConnectionConfig, DestinationGrant, IConfig) and the stores that hold it

Readme

@mcp-abap-adt/interfaces-auth-broker

The broker's port: what a destination states — its connection settings, how it renews its credential — and the stores that hold it. Types only; no implementation.

npm install @mcp-abap-adt/interfaces-auth-broker

| symbol | what it is | |---|---| | IConnectionConfig | a destination's connection settings, as a store hands them to the broker: serviceUrl, sapClient, language, the credential (authorizationToken, username/password, sessionCookies), authType, grantType, expiresAt, what a stored secret is bound to (issuedFor, issuedBy), and the settings a grant needs — SNC (snc*), OIDC (oidc*) and the SAML IdP's trust (saml*) | | DestinationGrant | how a destination obtains a new credential: the UAA, OIDC and SAML grants, or 'none' — handed over, not renewed | | IConfig | Partial<IAuthorizationConfig> & Partial<IConnectionConfig> — what a session store loads and saves | | ISessionStore | loads, saves and updates a destination's session | | IServiceKeyStore | reads a destination's service key as authorization and connection settings, and, optionally, its client certificate | | IClientCertificate | a client certificate a service key carries: uaaUrl, clientId, certificate, key, certUrl — answered by the optional IServiceKeyStore.getClientCertificate | | ITokenProviderResult | the result of authenticating a destination: its IConnectionConfig and a refresh token |

import type { IConnectionConfig, ISessionStore } from '@mcp-abap-adt/interfaces-auth-broker';
import type { IAuthorizationConfig, ISapConfig } from '@mcp-abap-adt/interfaces-auth-sap';

Why this package exists

interfaces-auth-sap 1.x held two subjects. One is the SAP system and the UAA client — ISapConfig, IAuthorizationConfig, XSUAA, the certificate loader — which a token provider, the ABAP connection and the ADT clients take. The other is the destination and its storage, which only the stores, the broker and the servers that build a broker import. The broker states what it needs from a destination and the stores implement it: that is the broker's port, and its fields name the destination, not the SAP system. A contract lives in the package whose subject its own fields name (decision 35); decision 41 in the repository's docs/architecture/DECISIONS.md records this split.

Kept apart, a release of the destination — new grant settings for the broker — no longer asks every provider and connection to follow, and a change to the SAP system's configuration no longer reaches the stores.

For store authors: the secret's binding (1.1.0)

A session store keeps two strings beside the secret — issuedFor, the canonical URI of the resource the secret was obtained for, and issuedBy, the canonical URI of who issued it and to which client — written and cleared with the secret. The broker (@mcp-abap-adt/auth-broker 4) uses a stored secret only when both equal what the destination's means give, so a secret never goes to another resource and a secret from another issuer is never used in place of this one. A custom ISessionStore (a database, a message log, a secret store) must persist both fields; one that drops them still type-checks, but the broker then never uses its sessions — every process start logs in afresh, a browser each time for an interactive grant. A key store never answers them.

Where these contracts were

@mcp-abap-adt/interfaces-auth-sap, until its 2.0.0 — same names, same shapes; only the package changed. Before that, @mcp-abap-adt/interfaces-adt until its 9.0.0. Not re-exported from interfaces-auth-sap: import them from here (decision 34).

Dependencies

Depends on @mcp-abap-adt/interfaces-auth-sap (^2.0.0 || ^3.0.0 — the one type it uses, IAuthorizationConfig, is the same in both), for IAuthorizationConfig — the UAA client a store returns beside the connection settings — and on nothing else. interfaces-auth and interfaces-utils reach it through that package.

Licence

LGPL-3.0-only.