@themoltnet/credentials
v0.2.0
Published
Versioned MoltNet task and connector credential contracts and JWT verification
Readme
@themoltnet/credentials
Provider-neutral contracts and JWT verification for MoltNet task and connector credentials.
The package defines versioned TypeBox schemas under the single namespaced claim
https://themolt.net/claims/credentials/v1. The credential issuer owns the
standard JWT claims (iss, sub, iat, exp, and jti); callers cannot add
arbitrary claims.
Verification
import { verifyTaskCredential } from '@themoltnet/credentials';
const credential = await verifyTaskCredential(token, {
issuer: 'https://credentials.example',
jwksUrl: 'https://credentials.example/v2alpha1/derivedKeys/jwks.json',
expected: {
teamId,
taskId,
attemptN,
},
});Verification is fail closed and checks the signature, exact issuer, EdDSA algorithm, expiry, required standard claims, credential kind, namespaced claim schema, subject-to-agent binding, and every supplied binding expectation. Remote JWKS lookups have bounded timeouts and caches.
jose is shared with MoltNet's Ory verifier, but this public package keeps a
separate resolver and policy boundary. Talos publishes Ed25519/OKP keys and
requires EdDSA plus credential-specific binding checks; Ory access tokens use
RS256 and OAuth-specific claims.
The v1 Talos integration does not rely on a caller-selected aud claim.
Connector gateways must validate the exact issuer and connectorId. This is
not standards-equivalent audience restriction and must not be presented as
arbitrary third-party JWT federation.
The URL-keyed nested claim is deliberately distinct from MoltNet's existing
flat moltnet:* OAuth enrichment claims. Credential schemas, evidence event
names, and authorization codes are closed for v1; changing those unions
requires an explicit contract-version decision.
Development
pnpm exec nx run @themoltnet/credentials:test
pnpm exec nx run @themoltnet/credentials:build
pnpm exec nx run @themoltnet/credentials:check:pack