Configuration
Last updated
This page lists every field of the Config passed to JWTAuth.init(), with defaults and validation rules.
Fields
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
privateKeyPath |
string |
One of two | — | Private key file path; overrides privateKey when set |
privateKey |
string |
One of two | — | Private key PEM content |
publicKeyPath |
string |
One of two | — | Public key file path; overrides publicKey when set |
publicKey |
string |
One of two | — | Public key PEM content |
accessTokenExpires |
number |
Yes | — | Access Token lifetime in seconds; also the revocation blacklist TTL |
refreshTokenExpires |
number |
Yes | — | Refresh ID lifetime in seconds, reset on every refresh |
isProd |
boolean |
Yes | — | Controls cookie secure, sameSite, and domain |
domain |
string |
When isProd |
— | Production cookie domain |
redis.host |
string |
Yes | localhost |
Redis host |
redis.port |
number |
Yes | 6379 |
Redis port |
redis.password |
string |
No | — | Redis password |
redis.db |
number |
No | 0 |
Redis database index |
checkUserExists |
(userId: string) => Promise<boolean> |
Yes | — | Confirms the user still exists during refresh |
AccessTokenCookieKey |
string |
Required by type | access_token |
Access Token cookie name |
RefreshTokenCookieKey |
string |
Required by type | refresh_id |
Refresh ID cookie name |
init Validation and Errors
| Situation | Result |
|---|---|
Neither publicKey nor publicKeyPath |
Throws publicKey is required |
Neither privateKey nor privateKeyPath |
Throws privateKey is required |
| Key path does not exist | The readFileSync error propagates unchanged |
| Redis connection fails | Logged with console.error, then thrown |
init() mutates the config object you pass: loaded keys are written back to publicKey / privateKey, and cookie names receive their defaults.
Key Sources
import { JWTAuth } from "@pardnchiu/jwt-auth";
// Read PEM content from environment variables, convenient for containers
await JWTAuth.init({
privateKey: process.env.JWT_PRIVATE_KEY,
publicKey: process.env.JWT_PUBLIC_KEY,
accessTokenExpires: 900,
refreshTokenExpires: 604800,
isProd: true,
domain: "example.com",
AccessTokenCookieKey: "access_token",
RefreshTokenCookieKey: "refresh_id",
redis: { host: "redis", port: 6379, password: process.env.REDIS_PASSWORD },
checkUserExists: async (userId) => true,
});
The package itself reads no environment variables.
Process Signals
Importing the package registers SIGINT and SIGTERM handlers that call JWTAuth.close() and then process.exit(0). If your app has its own graceful shutdown, note that this handler ends the process right after Redis disconnects.
Related: Token Transport, API Reference