pub struct AccessTokenResponse {
pub token: String,
pub subject: String,
pub expires_at: Option<Timestamp>,
pub session_id: String,
pub amr: Vec<String>,
pub credential_id: String,
pub grant_envelope: Vec<u8>,
pub owner_authorization: Option<OwnerAuthorizationBundle>,
}Fields§
§token: StringThe Biscuit (base64url-encoded). Goes in the heddle_session
cookie for browser flows and in the CLI credentials store for
device-bound flows.
subject: String§expires_at: Option<Timestamp>Unix-seconds expiry. The Biscuit also carries this internally, but exposing it explicitly lets clients know when to renew without parsing the token.
session_id: StringThe Biscuit’s session() fact (also its revocation id). Stable
public id surfaced in the Active Sessions UI; argument to
RevokeSession.
amr: Vec<String>§credential_id: Stringissued_credentials.id for tokens minted from a long-lived
credential row (device, service-account, agent). Empty for
browser sessions.
grant_envelope: Vec<u8>DEPRECATED, but still live and unchanged during cutover A1: Server-issued GrantEnvelope authenticating the client’s pubkey + session for biscuit minting. Existing Weft/Heddle consumers continue to use this as their single old authority until the later atomic cutover.
Owner-authored bundle returned without re-signing or reinterpretation. Empty until owner evidence is available; it does not supersede grant_envelope during this additive preparation step.
Trait Implementations§
Source§impl Clone for AccessTokenResponse
impl Clone for AccessTokenResponse
Source§fn clone(&self) -> AccessTokenResponse
fn clone(&self) -> AccessTokenResponse
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for AccessTokenResponse
impl Debug for AccessTokenResponse
Source§impl Default for AccessTokenResponse
impl Default for AccessTokenResponse
Source§impl Message for AccessTokenResponse
impl Message for AccessTokenResponse
Source§fn encoded_len(&self) -> usize
fn encoded_len(&self) -> usize
Source§fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self. Read moreSource§fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self.