feat: add server-side token storage with OBO caching - #136
Open
kishore7snehil wants to merge 5 commits into
Open
kishore7snehil wants to merge 5 commits into
kishore7snehil wants to merge 5 commits into
Conversation
Add pluggable server-side token storage and use it to cache On Behalf Of exchanges. When a token_store is configured, get_token_on_behalf_of() reuses previously exchanged tokens instead of hitting the token endpoint on every call. - AbstractTokenStore ABC with JWE at-rest encryption helpers - IndexedTokenStore for non-strict scope matching - OBO cache wiring in get_token_on_behalf_of() - scope_matching option: strict (exact match) or non_strict (coverage) - TokenSet, TokenIndexMember TypedDicts and VerifiedToken dataclass - TokenStoreError (status 500) for backend failures
kishore7snehil
marked this pull request as ready for review
October 6, 2026 06:46
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📋 Changes
This PR adds pluggable server-side token storage to auth0-api-python and uses it to cache On Behalf Of exchanges. When a token store is configured,
get_token_on_behalf_of()(already in main from a prior PR) reuses previously exchanged tokens instead of hitting the token endpoint on every call.✨ Features
AbstractTokenStoreABC for server-side token persistence, with JWE-at-rest encrypt and decrypt helpers built in. Subclasses implementget,set, anddelete.IndexedTokenStorevariant that maintains a scope index, required for non-strict scope matching.get_token_on_behalf_of()now caches exchanged tokens whentoken_storeis set.scope_matchingoption. "strict" reuses a cached token only on an exact scope match. "non_strict" reuses a cached token when its granted scopes cover the request, and requires anIndexedTokenStore.encryption.pymodule providing the JWE helpers used by the store.TokenSetandTokenIndexMemberTypedDicts and aVerifiedTokendataclass.🔧 API Changes
token_store(AbstractTokenStore, defaultNone) toApiClientOptions. When set, OBO exchanges are cached.scope_matching(str, default"strict") toApiClientOptions. Using "non_strict" without anIndexedTokenStoreraisesConfigurationError.AbstractTokenStore,IndexedTokenStoreTokenSet(TypedDict),TokenIndexMember(TypedDict),VerifiedToken(dataclass)TokenStoreError(status 500), raised when the configured store backend failsGetTokenByExchangeProfileError📖 Documentation
docs/TokenStorage.mdcovering theAbstractTokenStorecontract, a Redis implementation example, and the scope matching modesREADME.mdwith a token storage sectionEXAMPLES.mdwith token storage and caching examples🧪 Testing
Contributor Checklist