# API Reference

This page lists the signature, behavior, and errors of every public `JWTAuth` method.

## Import

```typescript
import { JWTAuth } from "@pardnchiu/jwt-auth";
// or the default import
import JWTAuth from "@pardnchiu/jwt-auth";
```

`JWTAuth` has only static methods; its constructor is private and cannot be called with `new`.

## Methods

| Method | Signature |
|---|---|
| `init` | `init(config: Config): Promise<void>` |
| `close` | `close(): Promise<void>` |
| `CreateJWT` | `CreateJWT(req: Request, res: Response, user: AuthData): Promise<TokenResult>` |
| `VerifyJWT` | `VerifyJWT(req: Request, res: Response): Promise<VerifyResult>` |
| `RevokeJWT` | `RevokeJWT(req: Request, res: Response, refresh_id?: string): Promise<void>` |
| `GetAuth` | `GetAuth(auth: AuthData \| number)` |

### init

Loads keys, applies cookie name defaults, and connects to Redis. See [Configuration](/configuration) for errors.

### close

Disconnects from Redis and clears the connection reference. Logs and rethrows when disconnecting fails.

### CreateJWT

| Step | Behavior |
|---|---|
| 1 | Computes the fingerprint and derives a Refresh ID |
| 2 | Signs an ES256 Access Token with `id`, `name`, `email`, `thumbnail`, `level`, `role`, `scope` (default `[]`), `fp`, and `refresh_id` |
| 3 | Writes `refresh:<id>` (`version: 1`) with TTL `refreshTokenExpires` |
| 4 | Sets the access and refresh cookies |

Returns `{ token, refresh_id }`. Throws `JWTAuth not initialized. Call JWTAuth.init() first.` when not initialized.

### VerifyJWT

Verifies the Access Token; on expiry it refreshes and writes back cookies and `X-New-*` headers. It throws only when not initialized; every other failure is a `VerifyResult` (see [Verification Results](/verify-results)). Refresh details are in [Refresh Token Rotation](/token-refresh).

### RevokeJWT

Clears cookies, shortens the refresh data TTL, and blacklists the Access Token. The `refresh_id` argument takes precedence over the request. Redis errors are logged, not thrown. See [Token Revocation](/token-revocation) for cases where nothing is revoked.

### GetAuth

Converts a legacy `VerifyJWT()` return value (`AuthData` or `400` / `401`) into `{ ...data, isAuth, isError, isGuest }`.

Related: [Types](/types)
