Skip to content

feat: add caching for Token Vault connection token exchanges - #139

Open
kishore7snehil wants to merge 1 commit into
feat/obo-token-storagefrom
feat/token-vault-caching
Open

kishore7snehil wants to merge 1 commit into
feat/obo-token-storagefrom
feat/token-vault-caching

Conversation

@kishore7snehil

Copy link
Copy Markdown
Contributor

📋 Changes

This PR extends the token store added in the previous PR to also cache Token Vault exchanges. When a token store is configured, get_access_token_for_connection() reuses a previously exchanged connection token instead of hitting the token endpoint on every call.

✨ Features

  • Token Vault Caching: get_access_token_for_connection() caches exchanged tokens when token_store is set. Entries are keyed by tenant, client, caller sub and connection, so one caller or connection never gets another's token.
  • Fail-Open Store Handling: A store read or write failure is logged and the exchange proceeds normally. A malformed or expired entry counts as a cache miss.
  • No Caching Without sub: If the verified token has no usable sub claim, the cache is skipped with a warning.

🔧 API Changes

  • Added an optional keyword argument verified (VerifiedToken, default None) to get_access_token_for_connection(). Callers that have already verified the token (for example an MCP server) can pass it to avoid a second verification. When omitted and a token store is configured, the token is verified before any cache lookup.
  • get_access_token_for_connection() now raises VerifyAccessTokenError when a store is configured and the token fails verification, or when verified does not match the access token being exchanged.
  • The result now always includes expires_in alongside access_token, expires_at and scope.

📖 Documentation

  • Updated EXAMPLES.md with a Token Vault section covering a basic call and caching
  • Updated README.md and docs/TokenStorage.md to mention Token Vault caching

🧪 Testing

  • This change adds test coverage
  • This change has been tested on the latest version of the platform/language

Contributor Checklist

🤖 Generated with Claude Code

@kishore7snehil
kishore7snehil marked this pull request as ready for review October 6, 2026 06:55
@kishore7snehil
kishore7snehil requested a review from a team as a code owner October 6, 2026 06:55

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant