Token Transport
Last updated
This page explains where the package reads tokens from a request, where it writes new tokens, and which cookie attributes it sets.
Read Order
| Value | First | Fallback |
|---|---|---|
| Access Token | authorization: Bearer <token> header |
cookie AccessTokenCookieKey (default access_token) |
| Refresh ID | X-Refresh-ID header |
cookie RefreshTokenCookieKey (default refresh_id) |
| Device ID | X-Device-ID header |
req.body.deviceId |
Cookies are read from req.cookies, so mount cookie-parser first.
Write Locations
| When | Writes |
|---|---|
CreateJWT() |
Access cookie, refresh cookie; return value { token, refresh_id } |
VerifyJWT() on refresh |
Access cookie, refresh cookie, X-New-Access-Token, X-New-Refresh-ID |
RevokeJWT() |
Clears both cookies |
Cookie Attributes
| Attribute | isProd: true |
isProd: false |
|---|---|---|
httpOnly |
true |
true |
secure |
true |
false |
sameSite |
none |
lax |
domain |
config.domain |
localhost |
path |
/ |
/ |
| Lifetime | Access: accessTokenExpires; refresh: refreshTokenExpires |
Same |
Related: Client Integration, Configuration