Skip to main content

oakquant-tokens

The shared token contract for the OakQuant platform — the single source of truth for the access-token format so the issuer (Canopy) and every verifier (grove, ranger, …) cannot drift.

Deliberately tiny: depends only on authlib + cryptography. No service-level coupling — unlike depending on the full timber-common, any service can adopt this without inheriting a database/ORM/encryption stack.

from oak_tokens import (
    TokenSigner, TokenVerifier, TokenContext, TokenError,
    JwksClient, build_jwks, public_jwk,
    generate_ed25519_keypair, compute_kid, public_pem_from_private,
)

Roles

  • Issuer (Canopy): holds the Ed25519 private key, mints JWTs with TokenSigner, publishes the public half via build_jwks / public_jwk at /.well-known/jwks.json.
  • Verifiers (grove, ranger): verify with TokenVerifier, resolving the signing key from the issuer's JWKS via JwksClient (rotation-friendly) or a static public key. Returns a TokenContext.

Claim schema

Header: alg=EdDSA, kid, typ=JWT. Payload: iss, sub, aud, exp, iat, jti, scope, client_id, tenant_id, actor_kind, roles[].

Algorithm allow-list excludes none; iss/aud/exp and required claims are enforced. An optional revocation_check callback supports a jti/introspection revocation fallback for sensitive operations.

Metadata

Release files for oakquant-tokens 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for oakquant-tokens 0.1.0
File Size Uploaded
oakquant_tokens-0.1.0.tar.gz 7.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for oakquant-tokens 0.1.0
File Interpreter ABI Platform
oakquant_tokens-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 18.0 kB

Release files / oakquant_tokens-0.1.0.tar.gz

Download URL oakquant_tokens-0.1.0.tar.gz
Size 7.6 kB
Tags Source
SHA-256 checksum
How to use checksums
5e47dd19fb669abc8b320a45d50fe0e3432bdd408320b63ff79916d3bd21840c
BLAKE2b-256 checksum
How to use checksums
f1925976630c2fc244f91e2f5fa7434936d83327b6bcdeae8d1076ebf70548c4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.0.1 CPython/3.13.13 Linux/6.17.0-1015-azure

Release files / oakquant_tokens-0.1.0-py3-none-any.whl

Download URL oakquant_tokens-0.1.0-py3-none-any.whl
Size 10.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ec2152dff324ce449cd1f5383487d1b91ab447f92e9f275c94d97488c4577279
BLAKE2b-256 checksum
How to use checksums
35695c0cd79da3f6c91934cf074ad2bc0e6aff66f43544fae3a24ed6054cffb7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.0.1 CPython/3.13.13 Linux/6.17.0-1015-azure

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page