oakquant-tokens
The shared token contract for the OakQuant platform — the single source of truth for the access-token format so the issuer (Canopy) and every verifier (grove, ranger, …) cannot drift.
Deliberately tiny: depends only on authlib + cryptography. No service-level
coupling — unlike depending on the full timber-common, any service can adopt
this without inheriting a database/ORM/encryption stack.
from oak_tokens import (
TokenSigner, TokenVerifier, TokenContext, TokenError,
JwksClient, build_jwks, public_jwk,
generate_ed25519_keypair, compute_kid, public_pem_from_private,
)
Roles
- Issuer (Canopy): holds the Ed25519 private key, mints JWTs with
TokenSigner, publishes the public half viabuild_jwks/public_jwkat/.well-known/jwks.json. - Verifiers (grove, ranger): verify with
TokenVerifier, resolving the signing key from the issuer's JWKS viaJwksClient(rotation-friendly) or a static public key. Returns aTokenContext.
Claim schema
Header: alg=EdDSA, kid, typ=JWT. Payload:
iss, sub, aud, exp, iat, jti, scope, client_id, tenant_id, actor_kind, roles[].
Algorithm allow-list excludes none; iss/aud/exp and required claims are
enforced. An optional revocation_check callback supports a jti/introspection
revocation fallback for sensitive operations.
Metadata
Release files for oakquant-tokens 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| oakquant_tokens-0.1.0.tar.gz | 7.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| oakquant_tokens-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.0 kB
Release files / oakquant_tokens-0.1.0.tar.gz
| Download URL | oakquant_tokens-0.1.0.tar.gz |
|---|---|
| Size | 7.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5e47dd19fb669abc8b320a45d50fe0e3432bdd408320b63ff79916d3bd21840c
|
|
BLAKE2b-256 checksum How to use checksums |
f1925976630c2fc244f91e2f5fa7434936d83327b6bcdeae8d1076ebf70548c4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
poetry/2.0.1 CPython/3.13.13 Linux/6.17.0-1015-azure
|
Release files / oakquant_tokens-0.1.0-py3-none-any.whl
| Download URL | oakquant_tokens-0.1.0-py3-none-any.whl |
|---|---|
| Size | 10.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ec2152dff324ce449cd1f5383487d1b91ab447f92e9f275c94d97488c4577279
|
|
BLAKE2b-256 checksum How to use checksums |
35695c0cd79da3f6c91934cf074ad2bc0e6aff66f43544fae3a24ed6054cffb7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
poetry/2.0.1 CPython/3.13.13 Linux/6.17.0-1015-azure
|