Skip to main content

OAuth2Client

An OAuth2 client, used to interact with a given authorization server.

Index

Constructors

constructor

Properties

optionaladditionalHttpHeaders

additionalHttpHeaders?: [String: String]

Additional HTTP headers to include in outgoing network requests.

readonlyconfiguration

The configuration that identifies this OAuth2 client.

optionalreadonlyjwks

jwks?: JWKS

The JWKS key set for this org.

This value will be nil until the keys have been retrieved through the `jwks(completion:)` or `jwks()` functions.

readonlynetwork

network: any

The URLSession used by this client for network requests.

optionalreadonlyopenIdConfiguration

openIdConfiguration?: OpenIdConfiguration

The OpenID configuration for this org.

This value will be nil until the configuration has been retrieved through the `openIdConfiguration(completion:)` or `openIdConfiguration()` functions.

Methods

exchange

  • Attempts to exchange, and verify, a token from the supplied request.

    This also ensures the JWKS keyset is retrieved in parallel (if it hasn't already been cached), and verifies the ID and Access tokens to ensure validity.


    Type parameters

    • T: TokenRequest

    Parameters

    • tokenRequest: T

    Returns Promise<APIResponse<Token>>

fetchJwks

  • fetchJwks(): Promise<JWKS>
  • Retrieves the org's JWKS key configuration.

    If this value has recently been retrieved, the cached result is returned.

    @throws

    OAuth2Error if the operation fails.


    Returns Promise<JWKS>

    The JWKS configuration for the org identified by the client's base URL.

fetchOpenIdConfiguration

introspect

  • introspect(token: Token, type: TokenType): Promise<TokenInfo>
  • Introspects the given token information.

    • Parameters:
    @throws

    OAuth2Error if the operation fails.


    Parameters

    • token: Token

      Token to introspect

    • type: TokenType

      The type of value to introspect.

    Returns Promise<TokenInfo>

refresh

  • Attempts to refresh the supplied token, using the Token.refreshToken if it is available.

    This method prevents multiple concurrent refresh requests to be performed for a given token, though all applicable completion blocks will be invoked once the token refresh has completed.

    @throws

    OAuth2Error if the refresh fails.


    Parameters

    • token: Token

      Token to refresh.

    Returns Promise<Token>

    The new Token created from the refresh.

revoke

  • Attempts to revoke the given token.

    A Token object may represent multiple token types, such as Token.accessToken or Token.refreshToken. These individual token types can be targeted to be revoked.

    • Parameters:
    @throws

    OAuth2Error if the revoke operation fails.


    Parameters

    Returns Promise<void>

userInfo

  • userInfo(token: Token): Promise<any>
  • Fetches the UserInfo associated with the given token.

    • Parameters:
    @throws

    OAuth2Error if the operation fails.


    Parameters

    • token: Token

      Token to retrieve user information for.

    Returns Promise<any>