{"_id":"@byu-oit/okta","_rev":"10-873b6a79934cd8a190ba686e6307b3ee","name":"@byu-oit/okta","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@byu-oit/okta","version":"1.0.0","keywords":[],"author":"","license":"ISC","_id":"@byu-oit/okta@1.0.0","maintainers":[{"name":"yoshutch","email":"scott_hutchings@byu.edu"},{"name":"lehinpm","email":"lehi_alcantara@byu.edu"},{"name":"oscea","email":"it@byu.edu"},{"name":"stuft2","email":"spencer.tuft@gmail.com"},{"name":"pauldeden","email":"byu-oit-npmjs@byu.edu"},{"name":"mhailstone","email":"matthew.hailstone@gmail.com"},{"name":"gi60s","email":"james.speirs@gmail.com"},{"name":"arasmus8","email":"arasmus8@gmail.com"},{"name":"garygsc","email":"garygsc@gmail.com"},{"name":"byujol","email":"byujol@gmail.com"},{"name":"martingarn","email":"martin_garn@byu.edu"},{"name":"snelg","email":"github@snelg.com"},{"name":"mzroth","email":"mark_roth@byu.edu"},{"name":"byu-oit-bot","email":"npm-aaaaamoularhpuhbr2i4pnykyi@byu-oit.slack.com"}],"dist":{"shasum":"2b350f625aa66021995f2436edcf2e9900a0d71d","tarball":"https://registry.npmjs.org/@byu-oit/okta/-/okta-1.0.0.tgz","fileCount":34,"integrity":"sha512-ZeIKJxfrnTx+YPCAKDfHUsGvCjYYFJj1k+nTtNpj0sCad/xgdsW714uFNsdHGHao8RAbcZAFYTapGm6ryGd1Lw==","signatures":[{"sig":"MEYCIQDC1qXp+BkXU7TvJsXGndyt3AAHBD+Q8veeqWLeUuDi5AIhAPsz7P9Yx6qWvIsXKkVWZO9Pk+aZqQg0pX9TlNr6/T4E","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":202994,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJiDEd7CRA9TVsSAnZWagAAZj0P/RGoYvp4BekXCyU3JBZN\ne+kee/gegheqSlk+3Sp6JbGQxfHdmOfjWvIPFbX8nC/EBFlA7weeaZMXLcXz\n4rRRLI219ozix1xYYaLZIC4YqhAx84KUx0Pwvs0Q+ia4uQV90sCvUNXdFi5Y\nTre91wN34lmz5ZdKwYX3yNIOpboZXgpkO6GCZMqdiD7FqjNbDH/ERmMacsoh\njZK44ULgkWDdqnCB/+ANSJ8atWT20uGbXJhLOu2PJCwA3qY2/EFbGfwTubYO\nzskspFm86I/hvEQVqDpYv62SHTWPbLHjSiJRy2eZFr3gTHshsrV3kuYUTEIh\nfmlkxEqPczEvYQJKg34fMHaZnuX2qNMSqT+aRLR3KFZM+12Rv6xKalEVcYd1\nkiBIaXFtzLeG0r9U0OMIoHsCSEy/z0uCBnHoN5AYMHIM2BbWLwwGC/Cnxrkm\nszneCo4VOB4dXENjQxC8vJwSTK42swlF4omYxW0iWj3j3fGQe09MOtlwSRUO\nX+60w0p0ZrNzuHX2JgeZSY11d5ivJufU5tNQvgMmmteEAlDHgkQRgCyNbgEF\nSNW42ixbvlnrRTIBq4A4sfqb3oJfp+x05r1kwDkLpskGF/LWVuVzlOP143A1\nL4KRMkU5ALDUShGqE4Y3vvIxzAyHv6/i4G8FJBR3JQUmkfT6B9HrA4c6WLcw\nbVpb\r\n=MJg5\r\n-----END PGP SIGNATURE-----\r\n"},"main":"index.js","gitHead":"0b5c51e2610d9b2825f8df6ee3b97e92b1680eb9","scripts":{"lint":"eslint .","test":"jest --colors","build":"tsc","lint:fix":"eslint . --fix","test:coverage":"jest --colors --coverage || exit 0"},"_npmUser":{"name":"gi60s","email":"james.speirs@gmail.com"},"deprecated":"This package is superseded by the byu-oit-sdk: https://github.com/byu-oit-sdk/javascript","_npmVersion":"7.23.0","description":"A tool for interacting with Okta using JavaScript in either NodeJS or the browser.","directories":{},"_nodeVersion":"14.17.0","dependencies":{"axios":"^0.25.0","debug":"^4.3.3","@okta/jwt-verifier":"^2.3.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^27.5.1","eslint":"^7.32.0","express":"^4.17.2","ts-jest":"^27.1.3","ts-node":"^10.5.0","supertest":"^6.2.2","typescript":"^4.5.5","@types/jest":"^27.4.0","@types/debug":"^4.1.7","@tsconfig/node16":"^1.0.2","@types/supertest":"^2.0.11","eslint-plugin-node":"^11.1.0","eslint-plugin-import":"^2.25.4","eslint-plugin-promise":"^5.2.0","@typescript-eslint/eslint-plugin":"^4.33.0","eslint-config-standard-with-typescript":"^21.0.1"},"_npmOperationalInternal":{"tmp":"tmp/okta_1.0.0_1644971899231_0.3207912803737718","host":"s3://npm-registry-packages"}}},"time":{"created":"2022-02-16T00:38:19.172Z","modified":"2026-07-06T18:20:22.487Z","1.0.0":"2022-02-16T00:38:19.420Z"},"license":"ISC","keywords":[],"description":"A tool for interacting with Okta using JavaScript in either NodeJS or the browser.","maintainers":[{"email":"scott_hutchings@byu.edu","name":"yoshutch"},{"email":"lehi_alcantara@byu.edu","name":"lehinpm"},{"email":"it@byu.edu","name":"oscea"},{"email":"stuft2@protonmail.com","name":"stuft2"},{"email":"matthew.hailstone@gmail.com","name":"mhailstone"},{"email":"arasmus8@gmail.com","name":"arasmus8"},{"email":"garygsc@gmail.com","name":"garygsc"},{"email":"github@snelg.com","name":"snelg"},{"email":"danielduraesm@gmail.com","name":"gholl0"},{"email":"developertools@byu.edu","name":"byu-oit-bot"},{"email":"micah.weatherhead@gmail.com","name":"mjweather"},{"email":"jvisker@byu.edu","name":"jvisker"}],"readme":"# Okta NodeJS\r\n\r\nA tool for interacting with Okta using JavaScript in either NodeJS or the browser.\r\n\r\n- [Examples](#examples)\r\n  - [API Development with OpenAPI Enforcer](#api-development-with-openapi-enforcer)\r\n  - [API Development with Express](#api-development-with-express)\r\n  - [Validate Access Token](#validate-an-access-token)\r\n  - [Validate that Claims Have a Specific Value](#validate-that-claims-have-a-specific-value)\r\n- [API](#api)\r\n  - [OktaClient](#oktaclient)\r\n  - [OktaVerifier](#oktaverifier)\r\n- [Debug](#debug)\r\n\r\n## Examples\r\n\r\n### API Development with OpenAPI Enforcer\r\n\r\n```js\r\nconst express = require('express')\r\nconst { OktaVerifier, OktaVerifierError } = require('@byu-oit/okta')\r\nconst Enforcer = require('openapi-enforcer')\r\nconst EnforcerMiddleware = require('openapi-enforcer-middleware')\r\n\r\nconst verifier = new OktaVerifier({\r\n  issuer: 'https://some-issuer.com', // the accepted issuer\r\n  aud: ['https://audience.com'], // an array of accepted audiences\r\n  clientId: ['client-id-1', 'client-id-2'] // an array of accepted clients\r\n})\r\n\r\nconst app = express()\r\n\r\n// initialize enforcer middleware\r\nconst enforcer = EnforcerMiddleware(Enforcer('./openapi.yml'))\r\napp.use(enforcer.init())\r\n\r\n// all routes must have these claims (use of an empty array is allowed) \r\napp.use(verifier.verifyAuthorizationHeader(['claim-1', 'claim-2']))\r\n\r\n// add enforcer route handlers\r\napp.use(enforcer.route({\r\n  persons: {\r\n    getPerson (req, res) {\r\n      // check if a claim is set to a specific value\r\n      if (req.jwt.claims['claim-3'] === true) {\r\n        res.send('You have access')\r\n      } else {\r\n        res.enforcer.status(403).send('Forbidden')\r\n      }\r\n    },\r\n    \r\n    updatePerson (req, res) {\r\n      // check if multiple claims exist\r\n      const error = verifier.verifyJwtClaims(req.jwt, ['claim-3', 'claim-4'])\r\n      if (error === null) {\r\n        res.send('You have access')\r\n      } else {\r\n        res.enforcer.status(403).send('Forbidden')\r\n      }\r\n    }\r\n  }\r\n}))\r\n\r\n// handle authorization errors\r\napp.use((err, req, res, next) => {\r\n  if (err instanceof OktaVerifierError) {\r\n    // choose how to handle the error\r\n    res.status(err.statusCode).send(err.message)\r\n  } else {\r\n    next(err)\r\n  }\r\n})\r\n```\r\n\r\n## API Development with Express\r\n\r\n```js\r\nconst express = require('express')\r\nconst { OktaVerifier, OktaVerifierError } = require('@byu-oit/okta')\r\n\r\nconst verifier = new OktaVerifier({\r\n  issuer: 'https://some-issuer.com', // the accepted issuer\r\n  aud: ['https://audience.com'], // an array of accepted audiences\r\n  clientId: ['client-id-1', 'client-id-2'] // an array of accepted clients\r\n})\r\n\r\nconst app = express()\r\n\r\n// all routes must have these claims\r\napp.use(verifier.verifyAuthorizationHeader(['claim-1', 'claim-2']))\r\n\r\n// route specific claims applying to anything under /persons\r\napp.use('/persons', verifier.verifyAuthorizationHeader(['claim-3']))\r\n\r\n// route specific claims appling to GET /persons\r\napp.get('/persons', verifier.verifyAuthorizationHeader(['claim-3']), (req, res) => {\r\n  // check if a claim is set to a specific value\r\n  if (req.jwt.claims['claim-3'] === true) {\r\n    res.send('You have access')\r\n  } else {\r\n    res.status(403).send('Forbidden')\r\n  }\r\n})\r\n\r\n// handle authorization errors\r\napp.use((err, req, res, next) => {\r\n  if (err instanceof OktaVerifierError) {\r\n    // choose how to handle the error\r\n    res.status(err.statusCode).send(err.message)\r\n  } else {\r\n    next(err)\r\n  }\r\n})\r\n```\r\n\r\n## Validate an Access Token\r\n\r\n```js\r\nconst { OktaVerifier, OktaVerifierError } = require('@byu-oit/okta')\r\n\r\nconst verifier = new OktaVerifier({\r\n  issuer: 'https://some-issuer.com', // the accepted issuer\r\n  aud: ['https://audience.com'], // an array of accepted audiences\r\n  clientId: ['client-id-1', 'client-id-2'] // an array of accepted clients\r\n})\r\n\r\n// adding claim checks here is optional and will ensure that the JWT also has the listed claims\r\nconst requiredClaims = ['claim-1']\r\nverifier.verifyAccessToken('some-access-token-value', requiredClaims)\r\n  .then(([ error, jwt ]) => {\r\n    if (error) {\r\n      console.log(error)\r\n    } else {\r\n      console.log(jwt)\r\n    }\r\n  })\r\n```\r\n\r\n## Validate that Claims Have a Specific Value\r\n\r\n```js\r\nconst { OktaVerifier } = require('@byu-oit/okta')\r\n\r\nconst verifier = new OktaVerifier({\r\n  issuer: 'https://some-issuer.com', // the accepted issuer\r\n  aud: ['https://audience.com'], // an array of accepted audiences\r\n  clientId: ['client-id-1', 'client-id-2'] // an array of accepted clients\r\n})\r\n\r\n// adding claim checks here is optional and will ensure that the JWT also has the listed claims\r\nconst requiredClaims = {\r\n  'claim-1': 'confirm' // claim-1 must have value 'confirmed'\r\n}\r\nverifier.verifyAccessToken('some-access-token-value', requiredClaims)\r\n  .then(([ error, jwt ]) => {\r\n    if (error) {\r\n      console.log(error)\r\n    } else {\r\n      console.log(jwt)\r\n    }\r\n  })\r\n```\r\n\r\n## API\r\n\r\nExported Types:\r\n- Jwt\r\n- OktaToken\r\n- OktaVerifierConfiguration\r\n- OktaVerifierRequiredClaims\r\n- OktaVerifierResult\r\n- WellKnown\r\n\r\nExported Functions:\r\n\r\n- axios\r\n- base64Decode\r\n- decodeJwt\r\n- getWellKnown\r\n- OktaClient\r\n- OktaVerifier\r\n- OktaVerifierError\r\n\r\n### OktaClient\r\n\r\n**Constructor**\r\n\r\n`new OktaClient (wellKnowUrl: string, clientId?: string, clientSecret?: string)`\r\n\r\n**Instance Functions**\r\n\r\n`getClientGrantToken (scope?: string): Promise<OktaToken>`\r\n\r\n`getWellKnown (): Promise<WellKnown>`\r\n\r\n### OktaVerifier\r\n\r\n`new OktaVerifier (configuration: OktaVerifierConfiguration)`\r\n\r\n**Instance Functions**\r\n\r\n`middleware (requiredClaims?: OktaVerifierRequiredClaims): (req, res, next) => void`\r\n\r\n`verifyAccessToken (accessToken: string, requiredClaims?: OktaVerifierRequiredClaims): Promise<OktaVerifierResult>`\r\n\r\n`verifyJwtClaims (jwt: Jwt, requiredClaims?: OktaVerifierRequiredClaims): null | OktaVerifierError`\r\n\r\n## Debug\r\n\r\nThis library includes the [debug](https://www.npmjs.com/package/debug) package. Debug logs are available by using the\r\nenvironment variable `DEBUG` set to `byu-okta:*`. \r\n","readmeFilename":"README.md"}