{"_id":"@adatechnology/keycloak-jwt","_rev":"2-d4ccab49e96296461f4245680ef1af39","name":"@adatechnology/keycloak-jwt","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@adatechnology/keycloak-jwt","version":"0.1.0","keywords":["bun","jose","jwt","keycloak","oidc"],"author":{"name":"Ada Technology"},"license":"MIT","_id":"@adatechnology/keycloak-jwt@0.1.0","maintainers":[{"name":"miyazaki","email":"andersonfrfilho@gmail.com"}],"dist":{"shasum":"bc581a50d4892e841b431d3161531fd1f3df92f2","tarball":"https://registry.npmjs.org/@adatechnology/keycloak-jwt/-/keycloak-jwt-0.1.0.tgz","fileCount":4,"integrity":"sha512-ALHHWeB5VNEyYLyo1MhiyCj0i6Ir/UMikC/+1IhmdVJHM6bqE3Duu05wi6pYHA6Pc1n1XtidItzhtvmDFRCg+Q==","signatures":[{"sig":"MEUCIQDlXRyft3CTabqK4EJvyLz7VMpvMM5cNov47aWRyOExsAIgQi1ul5x7gb0lFRnjIz7w3Qw21r0LgWeyzNCOciSskrs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16810},"main":"dist/index.js","type":"module","_from":"file:adatechnology-keycloak-jwt-0.1.0.tgz","types":"dist/index.d.ts","engines":{"bun":">=1.3.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"test":"bun test","build":"tsup","check":"tsc --noEmit","format":"prettier --write package.json src test tsconfig.json tsup.config.ts","format:check":"prettier --check package.json src test tsconfig.json tsup.config.ts"},"_npmUser":{"name":"miyazaki","email":"andersonfrfilho@gmail.com"},"_resolved":"/tmp/8c026ce23977511e8e06fb625a4eabf2/adatechnology-keycloak-jwt-0.1.0.tgz","_integrity":"sha512-ALHHWeB5VNEyYLyo1MhiyCj0i6Ir/UMikC/+1IhmdVJHM6bqE3Duu05wi6pYHA6Pc1n1XtidItzhtvmDFRCg+Q==","_npmVersion":"10.9.8","description":"Strict Keycloak access-token verification for Bun applications","directories":{},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"jose":"6.2.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/keycloak-jwt_0.1.0_1784463740274_0.0880546321715483","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@adatechnology/keycloak-jwt","version":"0.1.1","description":"Strict Keycloak access-token verification for Bun applications","type":"module","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"sideEffects":false,"engines":{"bun":">=1.3.0"},"keywords":["bun","jose","jwt","keycloak","oidc"],"author":{"name":"Ada Technology"},"license":"MIT","publishConfig":{"access":"public"},"devDependencies":{"tsup":"^8.5.1","typescript":"^5.9.3"},"dependencies":{"jose":"6.2.3"},"scripts":{"build":"tsup","check":"tsc --noEmit","test":"bun test","format":"prettier --write package.json src test tsconfig.json tsup.config.ts","format:check":"prettier --check package.json src test tsconfig.json tsup.config.ts"},"_id":"@adatechnology/keycloak-jwt@0.1.1","_integrity":"sha512-KJFapj3c5RQKGx74zJN83KxKYqBTMOnVs8J1OBw1EeQ94fl3XEOi1JceFoqf9CZGnuxPDGd2MjdwtziPO5xXtg==","_resolved":"/tmp/33602d27196ea9e75a3bcd07c0dfcde8/adatechnology-keycloak-jwt-0.1.1.tgz","_from":"file:adatechnology-keycloak-jwt-0.1.1.tgz","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-KJFapj3c5RQKGx74zJN83KxKYqBTMOnVs8J1OBw1EeQ94fl3XEOi1JceFoqf9CZGnuxPDGd2MjdwtziPO5xXtg==","shasum":"062b1791a689fcaa6d9c03944b694b11e585199a","tarball":"https://registry.npmjs.org/@adatechnology/keycloak-jwt/-/keycloak-jwt-0.1.1.tgz","fileCount":4,"unpackedSize":21136,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCBy8kCiHXEIL9rVvBfBdo18Iptg2eSDkKtoo/W3ojnXgIhAJMGXqW90S3jLjRJPEivrrhk99257u7MpZxdEtRDdjA+"}]},"_npmUser":{"name":"miyazaki","email":"andersonfrfilho@gmail.com"},"directories":{},"maintainers":[{"name":"miyazaki","email":"andersonfrfilho@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/keycloak-jwt_0.1.1_1784479956177_0.10826770124188378"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-19T12:22:20.114Z","modified":"2026-07-19T16:52:36.506Z","0.1.0":"2026-07-19T12:22:20.413Z","0.1.1":"2026-07-19T16:52:36.321Z"},"author":{"name":"Ada Technology"},"license":"MIT","keywords":["bun","jose","jwt","keycloak","oidc"],"description":"Strict Keycloak access-token verification for Bun applications","maintainers":[{"name":"miyazaki","email":"andersonfrfilho@gmail.com"}],"readme":"# @adatechnology/keycloak-jwt\n\nStrict, ESM-only verification of Keycloak access tokens for Bun applications.\nIt verifies the JWT signature with a remote JWKS and requires issuer, audience,\nexpiration, subject, an allowed algorithm, and a `kid`.\n\n## Install in a Bun application\n\n```sh\nbun add @adatechnology/keycloak-jwt\n```\n\n## Verify an access token\n\n```ts\nimport { createKeycloakJwtVerifier } from '@adatechnology/keycloak-jwt'\n\nconst verifier = createKeycloakJwtVerifier({\n  issuer: 'https://identity.example.com/realms/transportada',\n  audience: 'transportada-api',\n  jwksUri: 'https://identity.example.com/realms/transportada/protocol/openid-connect/certs',\n  algorithms: ['RS256'],\n  requiredClaims: ['company_id'],\n  jwks: {\n    timeoutMilliseconds: 5_000,\n    cooldownMilliseconds: 30_000,\n    cacheMaxAgeMilliseconds: 600_000,\n    responseSizeLimitBytes: 1_048_576,\n  },\n})\n\nconst accessToken = await verifier.verify(token)\n```\n\n`issuer` and `jwksUri` must come from trusted application configuration, never\nfrom a token or request. HTTP JWKS endpoints are accepted only for loopback\nhosts, so local Bun tests can use a local identity provider.\n\n`verify` throws `KeycloakJwtVerificationError` with a stable `code`; callers\nshould convert it to their application's public authentication response without\nlogging the token or its claims.\n\nInvalid trusted configuration throws `KeycloakJwtConfigurationError` and must\nfail application startup rather than become an authentication response.\n\n## JWKS readiness\n\nCreating the verifier is synchronous and does not contact the identity\nprovider. Call `probeJwks()` explicitly from the application's readiness\ncheck:\n\n```ts\nconst probe = await verifier.probeJwks()\nif (!probe.ready) {\n  // Keep this instance out of service.\n}\n\nconst status = verifier.getJwksStatus()\nconst ready = status.hasUsableCachedKey && status.fresh\n```\n\nThe probe returns only a frozen `{ ready: boolean }` result. It reloads the\nremote JWKS without requiring a JWT and reports ready only after resolving a\npublic key with a non-empty `kid` under one of the configured algorithms. It\nnever returns the JWKS URL, key material, or remote error details.\n\nConcurrent probes share the same request. A fresh usable cache returns ready\nwithout another request, while failed probes are throttled by\n`cooldownMilliseconds` before recovery is attempted.\n\n`getJwksStatus()` returns only four booleans and never exposes the JWKS URL or\nkey material. The status also reports `reloading` and `coolingDown`. Cooldown\ncannot be disabled and `cacheMaxAgeMilliseconds` must be greater than or equal\nto it, so configuration cannot turn unknown-key traffic into a fetch storm.\n\n## Runtime contract\n\nThe package publishes only ESM JavaScript and TypeScript declarations under the\nroot export. It has no NestJS runtime or peer dependency and requires Bun 1.3+\nat runtime.\n","readmeFilename":"README.md"}