pub struct AuthplaneClient { /* private fields */ }Expand description
Authplane client — the entry point for AS discovery, token operations, and resource creation.
AuthplaneClient wires the production-ready runtime the SDK exposes by
default:
MetadataCachebacking AS-metadata discovery, withon_changecallbacks fired on rotation.JwksCachewith background refresh andkid-miss force-refresh semantics, shared with everyAuthplaneResourceobtained viaAuthplaneClient::resource. Its fetch target follows thejwks_uripublished by the AS: oncemetadata_refresh_secondshas elapsed, ordinary verification traffic re-reads the metadata document and rebinds JWKS fetching to the rotated URL (RFC 8414 §2).TokenCachecachingclient_credentialsresults with a TTL buffer.CircuitBreakerguarding every outbound AS call.- Optional
DpopProvidersupplying outbound DPoP proofs when an operation is called withSome(&DpopProofOptions).
Implementations§
Source§impl AuthplaneClient
impl AuthplaneClient
Sourcepub fn builder(issuer: impl Into<String>) -> AuthplaneClientBuilder
pub fn builder(issuer: impl Into<String>) -> AuthplaneClientBuilder
Build a builder seeded with SDK defaults.
Sourcepub async fn create(
issuer: &str,
fetch_settings: FetchSettings,
) -> Result<Self, AuthplaneError>
pub async fn create( issuer: &str, fetch_settings: FetchSettings, ) -> Result<Self, AuthplaneError>
Backwards-compatible constructor.
Mirrors the previous signature so existing callers keep compiling.
Wires the same defaults as AuthplaneClient::builder.
Sourcepub async fn discover(issuer: &str) -> Result<Self, AuthplaneError>
pub async fn discover(issuer: &str) -> Result<Self, AuthplaneError>
Convenience constructor using FetchSettings::default().
pub fn issuer(&self) -> &str
Sourcepub fn metadata(&self) -> &AuthorizationServerMetadata
pub fn metadata(&self) -> &AuthorizationServerMetadata
AS metadata as discovered when this client was built.
This is a snapshot, not a live view: it returns a borrow, so it
cannot hand out a document that a background rotation may replace.
The JWKS fetch target is not read from here — it follows the
rotating document (see MetadataCache and
metadata_refresh_seconds). Callers that need the current
endpoints should read them from
AuthplaneClient::metadata_cache, which re-fetches on its own
TTL.
Sourcepub fn jwks_cache(&self) -> Arc<JwksCache> ⓘ
pub fn jwks_cache(&self) -> Arc<JwksCache> ⓘ
Shared JWKS cache; passed into AuthplaneResource so token
verification benefits from background refresh + stale fallback.
Sourcepub fn metadata_cache(&self) -> MetadataCache
pub fn metadata_cache(&self) -> MetadataCache
Shared metadata cache.
Sourcepub fn token_cache(&self) -> Arc<TokenCache> ⓘ
pub fn token_cache(&self) -> Arc<TokenCache> ⓘ
Token cache for client_credentials results.
Sourcepub fn circuit_breaker(&self) -> Arc<CircuitBreaker> ⓘ
pub fn circuit_breaker(&self) -> Arc<CircuitBreaker> ⓘ
Circuit breaker guarding outbound AS calls.
Sourcepub fn dpop_provider(&self) -> Option<Arc<DpopProvider>>
pub fn dpop_provider(&self) -> Option<Arc<DpopProvider>>
Outbound DPoP provider, if configured via the builder.
Sourcepub fn auth_provider(&self) -> Option<Arc<dyn AuthProvider>>
pub fn auth_provider(&self) -> Option<Arc<dyn AuthProvider>>
Stored auth provider, if configured via the builder.
Sourcepub fn fetch_settings(&self) -> &FetchSettings
pub fn fetch_settings(&self) -> &FetchSettings
Fetch settings (HTTPS-only / SSRF / dev-mode policy).
pub fn auth(&self) -> AuthplaneAuth
Sourcepub fn prm_response(
&self,
resource: &str,
scopes: &[String],
) -> ProtectedResourceMetadata
pub fn prm_response( &self, resource: &str, scopes: &[String], ) -> ProtectedResourceMetadata
Client-level PRM convenience: emits a Mode-3 (DPoP-unconfigured) document.
Inbound DPoP advertising is per-resource state, so use
AuthplaneResource::prm_response
when serving PRM for a resource that may have inbound_dpop configured.
Sourcepub async fn client_credentials(
&self,
client_id: &str,
client_secret: &str,
scopes: &[String],
resources: &[String],
dpop: Option<&DpopProvider>,
) -> Result<TokenResponse, AuthplaneError>
pub async fn client_credentials( &self, client_id: &str, client_secret: &str, scopes: &[String], resources: &[String], dpop: Option<&DpopProvider>, ) -> Result<TokenResponse, AuthplaneError>
client_credentials grant with circuit-breaker + token-cache.
Pass Some(&proof_options) to attach an outbound DPoP proof; None
for the plain bearer path. DPoP-bound results bypass the token cache
(each call mints a fresh proof bound to the token endpoint).
Sourcepub async fn client_credentials_stored(
&self,
scopes: &[String],
resources: &[String],
dpop: Option<&DpopProvider>,
) -> Result<TokenResponse, AuthplaneError>
pub async fn client_credentials_stored( &self, scopes: &[String], resources: &[String], dpop: Option<&DpopProvider>, ) -> Result<TokenResponse, AuthplaneError>
client_credentials grant using the stored AuthProvider.
Returns Err if no auth provider was configured via the builder.
The provider’s auth_header() value is used as the Authorization
header for the token request.
Pass Some(&proof_options) to attach an outbound DPoP proof; None
for the plain bearer path. DPoP-bound results bypass the token
cache (mirrors AuthplaneClient::client_credentials).
Sourcepub async fn exchange_token(
&self,
client_id: &str,
client_secret: &str,
options: &TokenExchangeOptions,
dpop: Option<&DpopProvider>,
) -> Result<TokenResponse, AuthplaneError>
pub async fn exchange_token( &self, client_id: &str, client_secret: &str, options: &TokenExchangeOptions, dpop: Option<&DpopProvider>, ) -> Result<TokenResponse, AuthplaneError>
RFC 8693 token exchange (guarded by the circuit breaker).
Pass Some(&proof_options) to attach an outbound DPoP proof.
Sourcepub async fn introspect(
&self,
client_id: &str,
client_secret: &str,
token: &str,
dpop: Option<&DpopProvider>,
) -> Result<IntrospectionResponse, AuthplaneError>
pub async fn introspect( &self, client_id: &str, client_secret: &str, token: &str, dpop: Option<&DpopProvider>, ) -> Result<IntrospectionResponse, AuthplaneError>
RFC 7662 introspection (guarded by the circuit breaker).
Pass Some(&proof_options) to attach an outbound DPoP proof.
Sourcepub async fn revoke(
&self,
client_id: &str,
client_secret: &str,
token: &str,
dpop: Option<&DpopProvider>,
) -> Result<(), AuthplaneError>
pub async fn revoke( &self, client_id: &str, client_secret: &str, token: &str, dpop: Option<&DpopProvider>, ) -> Result<(), AuthplaneError>
RFC 7009 revocation (guarded by the circuit breaker).
Pass Some(&proof_options) to attach an outbound DPoP proof.
pub async fn resource( &self, resource: &str, scopes: &[String], ) -> Result<AuthplaneResource, VerifierError>
pub async fn resource_with_options( &self, resource: &str, scopes: &[String], options: ResourceOptions, ) -> Result<AuthplaneResource, VerifierError>
Sourcepub fn dpop_headers(
&self,
method: &str,
url: &str,
access_token: Option<&str>,
) -> Result<Vec<(String, String)>, AuthplaneError>
pub fn dpop_headers( &self, method: &str, url: &str, access_token: Option<&str>, ) -> Result<Vec<(String, String)>, AuthplaneError>
Build DPoP proof headers for downstream API calls.
Exposes the configured DpopProvider’s build_headers so
callers can attach a DPoP proof to outbound resource requests.
Returns Err if no DPoP provider was configured.