Token Transport

Last updated

This page explains where the package reads tokens from a request, where it writes new tokens, and which cookie attributes it sets.

Read Order

Value First Fallback
Access Token authorization: Bearer <token> header cookie AccessTokenCookieKey (default access_token)
Refresh ID X-Refresh-ID header cookie RefreshTokenCookieKey (default refresh_id)
Device ID X-Device-ID header req.body.deviceId

Cookies are read from req.cookies, so mount cookie-parser first.

Write Locations

When Writes
CreateJWT() Access cookie, refresh cookie; return value { token, refresh_id }
VerifyJWT() on refresh Access cookie, refresh cookie, X-New-Access-Token, X-New-Refresh-ID
RevokeJWT() Clears both cookies
Attribute isProd: true isProd: false
httpOnly true true
secure true false
sameSite none lax
domain config.domain localhost
path / /
Lifetime Access: accessTokenExpires; refresh: refreshTokenExpires Same

Related: Client Integration, Configuration

中文