{"_id":"@mcp-abap-adt/auth-providers","_rev":"41-0e3dca63c51317a7ea2601231ea8cebe","name":"@mcp-abap-adt/auth-providers","dist-tags":{"latest":"5.2.1"},"versions":{"0.1.0":{"name":"@mcp-abap-adt/auth-providers","version":"0.1.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.1.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"a1278ffc58ce29c0702b6bebfa2e95379a97e726","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.1.0.tgz","fileCount":25,"integrity":"sha512-RsOR2vF3HCuY8vuiwx1fEZNaEfhRvbW/F6ado035EcktE++JOXwlaa/bSAuHLetRDGQqv8TPzS4CVao+P5zKpw==","signatures":[{"sig":"MEQCIAZsUklMmnybWNiuphdhKsjGnEcTWyubI4p5BlgIrtNLAiB4txxOErWq56xj3Evdy6BLGEO16phX1NfeftSUoKb/zg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":55812},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"085660c71316be97dc00f64c3e729f80e5278571","scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/logger":"^0.1.0","@mcp-abap-adt/connection":"^0.1.13","@mcp-abap-adt/auth-broker":"^0.1.6","@mcp-abap-adt/auth-stores":"^0.1.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.1.0_1764808017631_0.5713305094901402","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@mcp-abap-adt/auth-providers","version":"0.1.1","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.1.1","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"8555d0a5becbfa380b22ad6194b5d750fe680ed5","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.1.1.tgz","fileCount":25,"integrity":"sha512-HCTs5xJ1QDt56xBZbW858R7XnAoBY1KktCkqBZJr/coReN08FPgu+IP2kMW3dZKJ6NpwQ/tqIKQdg4kufhOE9w==","signatures":[{"sig":"MEUCIQCIwO3F3EffuMCo+m5K/as/LW3KZKEjFTbJHq6zhdz1XQIgKPhKIOI9NBDoRM/ydd7LH/s/gqAlxzg9oL1XeF7/z1U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":60277},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"493454b35e412ed38c3a70d18a815263150dd537","scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"10.9.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"22.16.0","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/logger":"^0.1.0","@mcp-abap-adt/connection":"^0.1.14","@mcp-abap-adt/interfaces":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.1.1_1764871025664_0.9356210109210545","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@mcp-abap-adt/auth-providers","version":"0.1.2","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.1.2","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"f729e583e8cfb83cd4898c7b8d7e5c1ef9d22ff7","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.1.2.tgz","fileCount":25,"integrity":"sha512-6AJ0KZfiRnq1jkBr/WDA7T8m51ZII6K7W50ahi1s5e0ITKB9G8J8JY7PSbO0fX+l+bRDwNoeoh7fnZ8nyHtrfA==","signatures":[{"sig":"MEQCIHIWACOO4ozmHtcsTbmazqSm8iZ219dD/ZpuiNAiVSrtAiBtOkkVwwNUenDo7i4qc2T+IMUe4HKwTIRIbNum63OBvg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":60780},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"f6d904d7ea25e6cc49f4b9fb63e32a70a2b707ed","scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.4"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.1.2_1764933373614_0.700270334251407","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@mcp-abap-adt/auth-providers","version":"0.1.3","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.1.3","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"2a09fc6026f80f444f2d66174a0ff48276be7772","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.1.3.tgz","fileCount":25,"integrity":"sha512-b0mPhnFIk8fis4Uq/h4muOetoRgKXHVdZM4T4vnP/boj18y/9g7HkvgcGlJiLzPxFkqXAJQ2KhIgEO8P2+cbrA==","signatures":[{"sig":"MEUCIQDXC7X+n/Ndodtibu3H14lh0SflJi0weDCCNYwy0Bn+4wIgWJyOSxAway5zpcPJrKCWfcYvr5utV9j+b7P5HF/bbNk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":63933},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"cc7b9368c39a4c09b2e08e6a8086d23d96762fdc","scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"10.9.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"22.16.0","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.4"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.1.3_1765174345201_0.835571227496545","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@mcp-abap-adt/auth-providers","version":"0.1.4","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.1.4","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"0a59e5debd766d2ebaaf1590af3f74216e32e761","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.1.4.tgz","fileCount":28,"integrity":"sha512-HBfKLmvGyOEzfAYSI+JGFqmtFCVvTcuiKejDfyIyGwIqmDHshF5FJiueerISAILGv4Djfg+8FBpk+D0viufJVA==","signatures":[{"sig":"MEQCIFO+feFFnZtoXvPqJokfh9bHL4ua+Reg1SL0vnCpVDV7AiBZLmS/KRPKuiLuju+PyqZEVWGbqD81APcDcfKyAmI4BA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":69712},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"6f8e218884b98308e9b4917caf21ef8cd8a18845","scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.4"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.1.4_1765213337987_0.07254925912375088","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@mcp-abap-adt/auth-providers","version":"0.1.5","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.1.5","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"77b7098bc5fb5890e3f7646f86c7d92429f27b82","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.1.5.tgz","fileCount":28,"integrity":"sha512-XE8RQ5ru2A9TiNIBacO+cNiEoaaduNm6ib8d1GDwocPnnfwjONphLPOw1YkXrtjhYKmZ6F6PJjssBCFQQl4InA==","signatures":[{"sig":"MEQCIFkuQZCDjcImq9qZpk35Qof5fM6y9x1E0yNKvmcHvbxfAiB5S/ynh5s491koGIlxTaZ1JCZBK6xAiMXRaE3HzmBMGA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":69849},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"10.9.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"22.16.0","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.1.16"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.4"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.1.5_1765570348146_0.876546867203317","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"cb693b92c677e5cf6c2ceea3f66af5a4bee43108","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.0.tgz","fileCount":31,"integrity":"sha512-Ssjo69vgfOTze1eOy3zBsrYZoJ4MxtCHmu5+hPGS1OwffjP2heC5Jkc5P5bNKc1fCqZ9OBeKfiSHHGH4zJe6EQ==","signatures":[{"sig":"MEUCIQCVcenUHEK+OSJGxVT8YgsD+gTec+VOOFoUvikXTHgS4gIgaXPQAvNrOLn8BY7qX+pHmNNaAApCmo60wWcyotlLtjI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":90099},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"a357a0998682c11f626ebad54abc050f0f95164f","scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"24.12.0","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.4"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.0_1766155120538_0.3523289435310941","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.1","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.1","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"367c324de47334bb2ec8f637757b98317ebfa243","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.1.tgz","fileCount":31,"integrity":"sha512-R/dI73U/VAxXPaLL4mHBNM0GJqMpuFQQQsqToS96RUp66iNsquDwtn8plwd/ZIOKpRGn2HdGAx54lxoNMtDyoQ==","signatures":[{"sig":"MEQCIHmmIM0EOEgtZIjjkx28wgbM/g3C8tBK0ad7Msl2DikQAiBesdr7pxWZG5lOhSwh7LMb4fOKJOE9J9B0nLn/Luv4bw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":97083},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"c1379e6e3fe5f5231c2779c1d136f75de6a4c85d","scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"24.12.0","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.4"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.1_1766245066858_0.13323944552838918","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.2","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.2","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"6054484ff5da66e3ceec263fcb93ac99debf6918","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.2.tgz","fileCount":31,"integrity":"sha512-9Ute1/afzHpWUGupL8pYt47su7QSCCTK1SloWlGisnfgWmifdwDgSju0XVEmUNfx6ibVeNaZIKy5MzRcDlKggw==","signatures":[{"sig":"MEYCIQC1LYHHnXo76zb9HYOJfykodE02otuxsle58H2urqnl4QIhAJsvb4dZzk43M4fFZGTAaotva2z400Kd0iW8zC0t7hyh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":99487},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"a104df74bbd039c1bbdb38d4e2778ace05601903","scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"24.12.0","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.4"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.2_1766252744780_0.990814125993996","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.3","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.3","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"13cff7a875600e99a2c7ee634184890f88dc565f","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.3.tgz","fileCount":31,"integrity":"sha512-/VHENgcbrM6cMGarn04Vp4BQuPlj1bzyqS8oTomONi0ebo9bKotCxyHI8sF9n/hqzHyX38QoyuD56gY38qYIhA==","signatures":[{"sig":"MEUCIQC22qL+HF30YJxJ2epzG3soYbJC+f95l18zWsI0+dKTgwIgbNFHX5lMtMFE0nHi5fQ95G3B4gHqDUhQJQR5k5nlbEQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":103898},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"8a8fc591529e8df49411155b3cca0fe54a0f38d9","scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.4"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.3_1766305869734_0.742758638781509","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.4","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.4","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"85c16ec69e6b860779136164ba82ca5c7d974b26","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.4.tgz","fileCount":31,"integrity":"sha512-f/Ou8TupgB5RU8q6P6X/XEMH0QeQi27Ng5o2QuynGx82cEofTICAJcZbKhz5VsMfdZi7bMe+KLPXcm3yoUrTjg==","signatures":[{"sig":"MEYCIQC4cyLpy7CazmTLKX+EK7wOLtJnSiAPR75HaWXROIdJDAIhAIvkmfr3Oe7bnAE/W8U+nfS4Inx9LXwR/zUhahm6KBoK","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":107032},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"62f1e948edc2a6f8ddb8c51b94d1af1406630c63","scripts":{"test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run clean --silent && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","build:fast":"npx tsc -p tsconfig.json","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.4"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.4_1766328673322_0.6339325978367409","host":"s3://npm-registry-packages-npm-production"}},"0.2.5":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.5","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.5","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"48d2ac256aaa0753bdc62cff4fbf9ee1c6704fb7","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.5.tgz","fileCount":31,"integrity":"sha512-f+K0WwFG3klXBTqYeQAAhCxCNYDrZWp3SHilkgS3JpotLZVgM1TpSUU9Z5ngtr6ktXyNaa/Sa3/9hGsswm2RYw==","signatures":[{"sig":"MEYCIQCv77+v2AHY06xTvu7FnLfJPw8MMFKIZn8x8iKxLbIprAIhAO8qjslfqt9VXXwQ9mrQRuJbtFKDQozmPd0aZCka0xyq","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":109976},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"47908caf907d69d6a01b8538f35a52781e4808ac","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","@biomejs/biome":"^2.3.10","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.1","@mcp-abap-adt/auth-stores":"^0.1.4"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.5_1766408333792_0.4476964538163364","host":"s3://npm-registry-packages-npm-production"}},"0.2.6":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.6","keywords":["abap","sap","adt","jwt","authentication","token","provider","btp","xsuaa","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.6","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"b21b2d16789507c64bb882cd981c074eef5299b7","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.6.tgz","fileCount":53,"integrity":"sha512-duICCuaTq7S7JHNN06TNEcV2q3v+MDQGn/5jXZLs0ZrY+IDCCZHpxD7OnXqLT17e/b43Cxr8Kjp5tgZheWGFKg==","signatures":[{"sig":"MEQCIFZc17/aeDZ7jZDgTeMhzSxRycQuLhY9+8DwDeyy0tJLAiAexzDzMR2P4FJ4uvsIrv8QhT6kst4pJMx9M6lrcvl+Yg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":166489},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"4826e894438c02d838c52b44688f7a2d551dd30b","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker - XSUAA and BTP token providers","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.9"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.1.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","pino-pretty":"^13.1.3","@biomejs/biome":"^2.3.10","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^0.2.9"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.6_1766508333386_0.5616496168636933","host":"s3://npm-registry-packages-npm-production"}},"0.2.7":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.7","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.7","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"11d24104b1bab79c6b27ceb0a0bbf0e2515474f3","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.7.tgz","fileCount":47,"integrity":"sha512-5kJvYAMPRdbUo+PtZG9kBOiFelzXrqak/jKioBKwNvTSIJwPRCbfs/6V0r+rFGto6XkbuyFDcx4uh8PgEs37cw==","signatures":[{"sig":"MEQCIBr8yHcljougSo7CipVCDjrpAnzsbag5HLoWnI99aUK8AiAMTXl7g0AnT6IheRDKXeeVMaVBlJcj7OxUVM2I6kqYRw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":146341},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"31b01e0f1eee4efc55b2a95b819ed78919f1a377","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.14"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.1.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.10","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^0.2.9"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.7_1766605726241_0.6766273323729706","host":"s3://npm-registry-packages-npm-production"}},"0.2.8":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.8","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.8","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"52ea0a0809125c83bbc1060f742cce8c554b54aa","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.8.tgz","fileCount":47,"integrity":"sha512-gh772U9w9/w27CarpfY3MMVrdm9RnardtcACKBR4YAj+Rwy6C4WA3s49/JdWflYlmElWFR1ctYM8MogieAraXQ==","signatures":[{"sig":"MEUCIQDMtx+wjSsbD0yuNQ8nFdKVDL5ou1mBg5slQX9S3nIw3AIgaZ+yHYUu+eInGCBheu5RUVdEiLfSXd1yh6JZ9SIMcIY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":155873},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"c594cfc2969cc2b3950a1431ab8756ff9bc0327d","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.14"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.1.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.10","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^0.2.9"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.8_1766618053236_0.9678003475210102","host":"s3://npm-registry-packages-npm-production"}},"0.2.9":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.9","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.9","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"2ac242dec97ae5a910d09f8342d156f7293c4c38","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.9.tgz","fileCount":47,"integrity":"sha512-DDVnJxAXSQOlEkoBs3v0UY18LNon4PBRK7PvCcHHy73DrPKSmfa2dl/ElcUzCJ/OjaODibNgHwXUCWNgdpSoUQ==","signatures":[{"sig":"MEUCIQDJQE4SrPKycKA7r2lqiDmesV+/Z73FGGiCek7E09TTLwIgFxfJznIFiTtEwo2PYIVhM3nOrmuz2Zrmk8mqC+w7e3E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":163738},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"c1776f6bc8c57a083588d12ad6762a75fa55b468","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.14"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.1.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.10","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^0.2.9"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.9_1766647979787_0.5052661184563472","host":"s3://npm-registry-packages-npm-production"}},"0.2.10":{"name":"@mcp-abap-adt/auth-providers","version":"0.2.10","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@0.2.10","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"6b72fdcc470640e1d84ca1e4f68ae35de598d210","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-0.2.10.tgz","fileCount":47,"integrity":"sha512-TjkTvfisKA5kQD4Ra2jvsxu2Z1DKNRRpV733hhZBkKsbWwpOjIN5U/8xZRIU5q4aQ/qLUwLShT1U8E696vcN2A==","signatures":[{"sig":"MEYCIQDqfrsNL9+oP/ON/Ribo33q2WdeFqTsyUPI2XjCpPSnZQIhAKA5knWYu1QFxHqkDp2Ajop6M8pNHk7XOioLGSGCuZiP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":166428},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"40cce498f8e4ecf9724b8e479e544fcf7df9692c","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^0.2.14"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.1.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.10","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^0.2.9"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_0.2.10_1766649636324_0.7264174652957454","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@mcp-abap-adt/auth-providers","version":"1.0.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@1.0.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"c8a0d1a9f441bb1422632433b145fc21a2f693ca","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-1.0.0.tgz","fileCount":98,"integrity":"sha512-jxDWiQETiq0Ii2rFaj5y/GQ1qhHeMNrtPUVO0j5EEBP6jfTeLXDDotF8lFuLS5dChYInp0Cf8eDDS6mVa9eCaw==","signatures":[{"sig":"MEYCIQCNk6DUbxaQHPEkkTwwEoTHp4rgaJhLz/MNenk0ko58XQIhAPI/ZdB30ZRWppKqt0vetKD89XabSQSvIf1f0/suos8n","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":242136},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"09f27fdac1fc553270e2d8368359a34e80dd128d","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^2.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.1.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.10","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_1.0.0_1770753656905_0.6539847433045478","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@mcp-abap-adt/auth-providers","version":"1.0.1","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@1.0.1","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"2c4060b3a379b62160f77e68d2652ba91903e7ed","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-1.0.1.tgz","fileCount":98,"integrity":"sha512-pb31g8jAe+WJWJWSzDYMuaCy2wYwKdEV0i7xjSLnd3DDHzrFY+zfAb084zbUmaNKO7a2YvxsEk0H+bOM02SJog==","signatures":[{"sig":"MEQCIHKxSjrJxrMsZXPZd/pJ57vH0zAjthU7nYnQ2PsljL50AiBK0BgfLrzcmIvm+lnA5HjVdKhLCC2fPc+uOTDrDozUqg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":242228},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"76321873974810d8392885ad4aef7b7c36cf88cf","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.11.0","express":"^5.1.0","@mcp-abap-adt/interfaces":"^2.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.1.0","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^24.2.1","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.10","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_1.0.1_1770759149507_0.27911690551073853","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@mcp-abap-adt/auth-providers","version":"1.0.2","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@1.0.2","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"88c97f5a220ea380ffede0d2a2fa2b423bda561d","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-1.0.2.tgz","fileCount":101,"integrity":"sha512-1GqQn0GHEBR1RDkhnILXYmoezlpbnOC5aCM5YmAwN1QEeUyjVs6O1aylmmf2/xbcrpkTj+j9ap8lHMARWEPXJw==","signatures":[{"sig":"MEYCIQDsmGlKzhZbYzDKwCuqTW0oGrCMdTOKQu4C7S4ECS3ZhQIhANLBQHIZh/eKwibzAPuV0j3qOnbF22dfKPJGc68gxfHA","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":255095},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"55d3dcd3ca9f85344fa3176822eda54387bfe1fc","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@mcp-abap-adt/interfaces":"^2.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_1.0.2_1770798498461_0.17583708498668238","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@mcp-abap-adt/auth-providers","version":"1.0.3","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@1.0.3","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"166e91f7903b1059cc89bca6509dc9c1734ca932","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-1.0.3.tgz","fileCount":101,"integrity":"sha512-PQWpFEPl6AS9p2UOOUo/pCkJRKxPtSYN63b3RdcRWJBnC4bg6/sSwrs/BDzmsRLTTpI8ilN1H+1y+B96OExIrw==","signatures":[{"sig":"MEUCIGf6t6UOtg+zqSEhat8t0yjwUYStE92+5+U+spL4MPKwAiEAtAyEuUtwTeXce8f96VwEGBRmZUy/IqADDgiESZJ9KO0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":255248},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"80bda95aadbf3dee754a0a25434d012bf0bce23a","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@mcp-abap-adt/interfaces":"^2.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_1.0.3_1770829553649_0.8760715795245855","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@mcp-abap-adt/auth-providers","version":"1.0.4","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@1.0.4","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"51313db45cfbbbb2b26b3231f644554194c23524","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-1.0.4.tgz","fileCount":98,"integrity":"sha512-lPm7XpvXQ9BQ8LX8K0gK7npfprLX2HYCerZfngdpPYhSJJfyn3jvlYLvFC3nO4ycLy/QU81vTKJ7J8oftnv5eQ==","signatures":[{"sig":"MEYCIQDI0k8TTexhrjwQYABCOv/E16g/TYSzaWfKLMnTnX96kAIhAMLmykWVmr8D7NK/jWMukNJycuEnEL/aGxb7fPUR9YQX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":250308},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"d44e7a359099fefe075397675750233ad26aa40a","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@mcp-abap-adt/interfaces":"^2.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_1.0.4_1770831727262_0.21530602025881196","host":"s3://npm-registry-packages-npm-production"}},"1.0.5":{"name":"@mcp-abap-adt/auth-providers","version":"1.0.5","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@1.0.5","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"13be73607140d3ba93e8d005d81115f2bd423489","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-1.0.5.tgz","fileCount":98,"integrity":"sha512-jGCALUMoNv/cvMb1nP5gtLI2vye0lASHxdn1i1seG9C4BQo5DVFzNfnv6mvLB1z553DPl7Z1OlySwrf7PJ3G8Q==","signatures":[{"sig":"MEYCIQDr/DqSDJ3qpCOll/Sgxo/xAo8hUR7owjSwCgHGgkoHOgIhAM7KrQ7LZ8Jc9/XMsx2FK23e1njE8XCOn/h6e5wDjNtd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":250740},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"3eb1a56d1167c1604ba2fe5f0b8c831baf4f54d3","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.6.2","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"24.11.1","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@mcp-abap-adt/interfaces":"^2.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_1.0.5_1770876513573_0.10153781136205864","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@mcp-abap-adt/auth-providers","version":"1.1.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@1.1.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"a2bbbbe3835b84dc9153c0cf8ae9317e15cd75d7","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-1.1.0.tgz","fileCount":98,"integrity":"sha512-Vff9uT0pneKcIa4ClH+qB28kDIKYpmSbK029e+CpNzSn78CSbLh1demeHl6wU85twFLjMHUqJUcXoa0Su2Bq+w==","signatures":[{"sig":"MEQCID/ooAp6swusgZqP5e69JGpXPL3q91pbuBfs8V8xD+rFAiBUa7tyBr/PMEwC5C8z/nHvxHw8+xCnFLVTmvSX3oF5pg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":258361},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"a906da4538d9c7cd940239b771efc4941a60a333","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.12.1","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"25.9.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@mcp-abap-adt/interfaces":"^2.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_1.1.0_1780403122812_0.3429663969219523","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@mcp-abap-adt/auth-providers","version":"1.2.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@1.2.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"96b03c7fc3cd2f671e438e340f885604e7a9ffe4","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-1.2.0.tgz","fileCount":101,"integrity":"sha512-jYYCS/gl4sgTrxmlwucHawG9Bn93ZkZoxscvVbGGYowJX8W2Q+8RtfkTyLxM2agPaliIKiwJZPAkrHCu0HI08A==","signatures":[{"sig":"MEUCIQCL8SKFFtecIiqBTbiP7DJl4R79idIrtNWupZdKEPfVuAIgCf1laPryg3Y326m1f4TV0ylg40xj4tNqJtsf5b+kDA4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":262552},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.2.0"},"gitHead":"0cdb0e2ea6ce88ff8ee61e9b633818736523bc09","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.18.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"25.9.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@mcp-abap-adt/interfaces":"^11.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_1.2.0_1785270543722_0.6208920527636355","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@mcp-abap-adt/auth-providers","version":"2.0.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"MIT","_id":"@mcp-abap-adt/auth-providers@2.0.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"e07ed53113b2f6f792434e100b02ca01b59e34ba","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-2.0.0.tgz","fileCount":116,"integrity":"sha512-IjlIeZSLYC5X1NG++t0zeN7j+qqHFuCCkz/Btyn51tqKMDQxd1z8sxxoof8fulBeNjFMRLrCxJSFB3wKFX13QQ==","signatures":[{"sig":"MEYCIQDHCpjm/YKcNXP2xI6Ag7PbQlkZBxd2ry2v/GON52M/uwIhAML22tOWroBloEQnrY1iqg5QWKO25XgxJQc06Aao2/Aj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":309204},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.2.0"},"gitHead":"2dc54a23831e25a0733cc15360a6f6e36016f7df","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.18.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"25.9.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@mcp-abap-adt/interfaces":"^11.6.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.1.4","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_2.0.0_1785582167363_0.09149447520337883","host":"s3://npm-registry-packages-npm-production"}},"2.2.0":{"name":"@mcp-abap-adt/auth-providers","version":"2.2.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@2.2.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"873675abcd36337485962034557b6afc4dcc5dea","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-2.2.0.tgz","fileCount":117,"integrity":"sha512-6mh4THav1oPX40UnzXOsbvyAqaNLd5wP/kmvnzhDRkYSs1uLZ9KrsMrZxJWFF/fKLOSSSr78U9NKRkCJC8vFkQ==","signatures":[{"sig":"MEUCIQCPRtXAQ3I8LGyrc4RKdb3avgxMZ2u3hDSa2Lt9abWJfwIgfe8rIk2KMNYzg5ff13BLz0iA+YE3gAo/iV8kIzHJrYY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIGz53Z223GduW9yIh3p6Mk+DO0DBTEo55eJ210tcCLWlAiEAvdnn0Dly08tVRM+/Ts2qORQ9QK1VFMD/4071daS4q5g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":355475},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.2.0"},"gitHead":"3db6068339658d857931ad2755966ddce8ef0f07","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@mcp-abap-adt/interfaces-auth":"^1.2.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_2.2.0_1790196970018_0.9640331675964564","host":"s3://npm-registry-packages-npm-production"}},"2.2.1":{"name":"@mcp-abap-adt/auth-providers","version":"2.2.1","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@2.2.1","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"b7724355666c38da5a34e369fa62e198ff095c5c","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-2.2.1.tgz","fileCount":117,"integrity":"sha512-gmgslKqnZst8lA+9RvhKPG94R6ZR7xuFuKornj3mGFYOz0dHOYkS0Cmge4hDitQpmgVNfZqBIZ5ysOjOmNJhug==","signatures":[{"sig":"MEUCIFrG/2XASEOk2OsEzAPOs0kVdXWb4rXcfKM/XNrp71PwAiEA9To2+sgEF2a/a90gsCsfUYwJ4fKrjlk59PRvWATwU+8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCCYcujfLhAM0KPOn/5Vy6KHL3oBA69ANscZ4is9NZ0yQIhAONLFLHjS4Dr1BJac54rgtfH3WzFzM6pluz/UVTECgP7","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":359854},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.2.0"},"gitHead":"9e6aa13a91cf9a1dbc2924791571925781649c51","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@mcp-abap-adt/interfaces-auth":"^1.2.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_2.2.1_1790198724490_0.5639160447239324","host":"s3://npm-registry-packages-npm-production"}},"2.2.2":{"name":"@mcp-abap-adt/auth-providers","version":"2.2.2","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@2.2.2","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-device-flow":"bin/auth-device-flow.ts","auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"43e55117410551811962931cf9b053f3f69403e0","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-2.2.2.tgz","fileCount":117,"integrity":"sha512-cqXA4/mrvHKLwi1rCa8UkTBiaFrWA4WJGv8IDvcKJvtynSY604zoe1d21CcDwlkBaJpjdmoEjyEPAmiEBmrBMg==","signatures":[{"sig":"MEYCIQDOAIHdZHQPWFFIQZY6GKKZQFV6LDEswxGPXpT7xJQFuwIhAJPfVyAsXAuvl5EYqiTE0ZnQfMLIVn1Y8ZiUt1ANgVZw","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIE6lTrWSOdM+84UazgY9Wun+8licDakRQ9KOV0xMqla3AiEA7Tnj/xS/v/hahxVlf/ctFXnOb0fQwVf/3H0UhIz/tZ8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":360273},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=18.2.0"},"gitHead":"edf882ea3380ac30ebf367d22ab5878b2a7e7b81","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","test:check":"npx tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@mcp-abap-adt/interfaces-auth":"^1.2.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_2.2.2_1790235773260_0.531484145281738","host":"s3://npm-registry-packages-npm-production"}},"3.0.0":{"name":"@mcp-abap-adt/auth-providers","version":"3.0.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@3.0.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"8acef944f55e72628a67f9497ab6e6d1f87167b0","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-3.0.0.tgz","fileCount":122,"integrity":"sha512-OnuFeU5NFC87eyGJX8e3x3p5VK1SHmJUCzhpvUBPSAonQ/fjA/HoPaQX9G3HsTOuOiFAXQlwZOkf8gr7CQbSAA==","signatures":[{"sig":"MEUCIQDZaJwa8i3oajcnpAHdOyXly/cDqreJn8QpCv0QC7QmogIgbzRf0Av1Pk36Gs2dxW1T14WARFrpvxGIqL1Zn4YH5tw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIAZ7Ai0OU6Y3EvC3PFXvhzzT/nveEY9BgAkChGIrmUXmAiEA0DM/m0gF6K7YGncrgtrOIeb/NlRo1lF3fvCq81GhzqA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":391158},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24"},"gitHead":"acf9629873b5f567e7c83c86a12256d42f1bc64f","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^1.2.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_3.0.0_1790279764046_0.7128982918899334","host":"s3://npm-registry-packages-npm-production"}},"4.0.0":{"name":"@mcp-abap-adt/auth-providers","version":"4.0.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@4.0.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"bin":{"auth-authorization-code":"bin/auth-authorization-code.ts","auth-client-credentials":"bin/auth-client-credentials.ts"},"dist":{"shasum":"766dc9113aa1a1c1cbb26491a89a2b1e27834b81","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-4.0.0.tgz","fileCount":143,"integrity":"sha512-SlgolIZF+dEU8IXKgr4WIs2mQOR8VMVHUwbjxV+RPvAgQkWd8jwXJN6/8qFZ+z8otvVjuoieeXXZrifYgeQviA==","signatures":[{"sig":"MEYCIQDdCvK5iKVh2keXZIRIH2lRJGtcRPgfxtdMxiXaSs2xJQIhAOHUF7+ucbDCuRUU7tytWMw6xECsgIQGnrL65o8i3lze","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDEzUIFh2Ks9RowH8HBaTX2exbhQS5wXNQoZidMEW4C0gIhALdfjvDPctei8NScTXUIQgW4OQiecXBgU5O3qYE4iRnd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":496675},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24"},"gitHead":"3f3fa643257411e4e6b581d0555de69183fc67d0","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^2.0.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_4.0.0_1790340906219_0.04950813163413148","host":"s3://npm-registry-packages-npm-production"}},"4.1.0":{"name":"@mcp-abap-adt/auth-providers","version":"4.1.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@4.1.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"7505252c3f58b1159c77ff7de786ba89e704fea3","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-4.1.0.tgz","fileCount":140,"integrity":"sha512-oCaI5c2mcDdQrSyKHjF2emPu0CLznJ1tsMfBQuAgXz8cVtub4/e3BuYKYvirX9ssKwgTXAKaA7SF9rS0+sjGgg==","signatures":[{"sig":"MEUCIQC85gVKlklIIQ7WhcYG3jNxgZR2e5sHhfXS2nZEIjzHIAIgPTO+UGyPK4XSxRgZvYr8ZSuTRQ4410RkPcYNGNo9VdA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCofUEF5stRm8kCV3re4qpUiUnOG387koArOrnlaSQ51QIgHDVmbfaBkIuQcAfi1vwZFQYoAwmf6yEQFMSbhsIbU4s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":498419},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24"},"gitHead":"e3d812ae8990b49418e8070ca72c10e47505df9c","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.json","clean":"rm -rf dist tsconfig.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^2.0.1","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.0.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_4.1.0_1790404098171_0.036787497975860894","host":"s3://npm-registry-packages-npm-production"}},"4.1.2":{"name":"@mcp-abap-adt/auth-providers","version":"4.1.2","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@4.1.2","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"a115293f89385e2dbede555511f832905e8d1b01","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-4.1.2.tgz","fileCount":131,"integrity":"sha512-ZDF84VCZjvx2wP9oY4IT6JFtiaG4NrS8p4GaB0TCvg0uqzaCZM22R+gVg3GcXK+7/FFHOQmBtsGxDbRJS8XJFQ==","signatures":[{"sig":"MEYCIQDt5Px/tYj+eqRtjNqi6vpY1gLw5/WyLiU5oA04hQmUvAIhAOAPj74I4vY0a43xehpHCthgu9QVrYKika00bCKVqxNz","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIAQMfrgxRC30h7YNC+z0z/L9vw+dIzvLRDQu8urD9y0LAiAkdzlH1jPcLdzwyT7TK5jgLmRJ7hyZUWyeFNhTSkRAmg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":476190},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24"},"gitHead":"b7152262aa39fecfc9bf742156b3a3656d7d1f17","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.build.json","clean":"rm -rf dist tsconfig.tsbuildinfo tsconfig.build.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.build.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^2.0.1","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_4.1.2_1790422151013_0.9204373667464287","host":"s3://npm-registry-packages-npm-production"}},"4.1.3":{"name":"@mcp-abap-adt/auth-providers","version":"4.1.3","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@4.1.3","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"b4707268dce009e5b6c9daf56106ae7b0c79fa10","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-4.1.3.tgz","fileCount":131,"integrity":"sha512-6Ms5hT7YFdhwyEjOkHe8tmYxh61ImPdUo+AjqUlkB0obsFqGveO0H6jsA344huWjQm9WVl12b0k8N/wyRgyAzg==","signatures":[{"sig":"MEQCIFovUESCgI1zeLS5m3Dlq+IdT5P/OxKVTjtREBgn4cDDAiB83sf5hYfLI03ZPnf4wfgs/Q3nerKGYIXe2OTjY1C5DA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIFESTM+gjvHiYsAtBy8dZ35x5xaImATG/qiziqFj4Q1BAiEAlivYfCws4Z4mQDGEa3vbUxECxCu8Xdng964oZN1OhfU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":477007},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24"},"gitHead":"85ffd696a3070ca5fc5a5c6822570cb93cb9ddce","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.build.json","clean":"rm -rf dist tsconfig.tsbuildinfo tsconfig.build.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.build.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^2.0.1","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_4.1.3_1790425561595_0.9929062509147628","host":"s3://npm-registry-packages-npm-production"}},"4.2.0":{"name":"@mcp-abap-adt/auth-providers","version":"4.2.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@4.2.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"58fdd817d51d66f3f8d653b6f5a720716a968a54","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-4.2.0.tgz","fileCount":131,"integrity":"sha512-Cb+7Cq+z7Ce5W1DiDLs4jaLf8uS3ZBxZ+ccuZhqDvVJsg2yuSptxuVuG3C/oaanbw1kLeHgyoTwRJTl/eFcefA==","signatures":[{"sig":"MEQCIDoRrHI+CGa3WR447tXf2BOE7tPmKG6jVNndJXEV/wXkAiAiXS+OBeLwT4JF3gNPg3t5rM0jEGta/TaZeA5K+3OItQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIAOjTp7yO2kg8ZeltpRfQnJ7sOzk14hn760TJh6WxNBlAiA6NaP1guvBOPOkSFkp7GspibSF6ukI/w2SDfH1cvbRTQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":483086},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24"},"gitHead":"3d398d9b9d4478f782240424d72cde0fa07d926b","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.build.json","clean":"rm -rf dist tsconfig.tsbuildinfo tsconfig.build.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.build.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^2.1.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_4.2.0_1790428753375_0.40874449879635955","host":"s3://npm-registry-packages-npm-production"}},"4.2.1":{"name":"@mcp-abap-adt/auth-providers","version":"4.2.1","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@4.2.1","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"6102301a0eae0f5e12a1c71ebad769612b2faec9","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-4.2.1.tgz","fileCount":131,"integrity":"sha512-q0jGMsjPkdUp1i4WgxG+F8q4vyRTnDiPGa+Fam+1v/Fyvb0ZEeBrBiXZyLZJESIBr37WBWeNjLpbbpQWwKd2uQ==","signatures":[{"sig":"MEUCIQCUSk0rbovEm/rgDSKdzagCPdXlF6ps1qTzQyucTh0+KAIgfayagAfldEhlKZ9QYVeQzXIBzG6LeDNRS3aYPaJ7LM4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDACB7FH7F2JrxZvfnkL9E2f+Ko4A2CGGFhr61zMj49gQIgPMqpa73za/83AfeIb7qEWo5MCNy+kkwfF3C7zgxrCls=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":483566},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24 || ^26"},"gitHead":"35de890cdad4ac3ce9da9c377792657457fc7bb1","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.build.json","clean":"rm -rf dist tsconfig.tsbuildinfo tsconfig.build.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.build.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Token providers for MCP ABAP ADT auth-broker","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^2.1.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_4.2.1_1790526181224_0.16180555738073066","host":"s3://npm-registry-packages-npm-production"}},"5.0.0":{"name":"@mcp-abap-adt/auth-providers","version":"5.0.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@5.0.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"127187c1ce3f101083ef2ac9ff65b2c94ba8bfb1","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-5.0.0.tgz","fileCount":173,"integrity":"sha512-oS8hHUosX1Ccx61hLrs71KFf6qRlq9n+GkUZtrjUhtUX07UJRldfQmdjCfqcCS4gbjtFEDVQGGdWmwmIOdEsGQ==","signatures":[{"sig":"MEUCIQDa4zMkU6I5vVOHBRUV16n+8MPZ7VhXoCg/J9gzDarT9QIgBveknGWiUEuh77jvheVQ42rjBs8l84LOn9n05H0mYJo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQC05E9haR5QjZNcdlLEo1Nn8mtdrF5pPpOjTnTB9JII9gIhAOrXvWODrxYo/NcbCoAcr/BoQb5WZnnCNd6mlbW3xjb6","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":585491},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24 || ^26"},"gitHead":"9cd55a58e2e274ff836a6cc1157b81730b5b590e","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.build.json","clean":"rm -rf dist tsconfig.tsbuildinfo tsconfig.build.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.build.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Every IAuthProvider for SAP ABAP ADT: the credentials a process delegates to, and the token providers behind them","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^3.0.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_5.0.0_1790723460493_0.0668255610205597","host":"s3://npm-registry-packages-npm-production"}},"5.0.1":{"name":"@mcp-abap-adt/auth-providers","version":"5.0.1","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@5.0.1","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"32243250cdbef5f158b37c6c98b11daa1b63ad5b","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-5.0.1.tgz","fileCount":176,"integrity":"sha512-CO3CrQIQdq0OUrh9X4jLsvwMUMEYufVVyOm8+O59RnepgmCdEYxzDePIMIylt4/Fu6hVCtry9p/xhuDmdL+4Nw==","signatures":[{"sig":"MEUCIE6W0JxDKpctoJ0s2Y5ixyFJLfe9m0+JOkMWObX2v0Z0AiEA95N7uEHFOJfb3WLWc4fZaQjs0dWu/5ck9KhJEtXqyLo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIGf3sjqsF9OQ+ZUQZXSt60LztxIwKJR1C2Gte83TodCbAiEA1EQq1Fce8Br6HgM0zRcbIahDrRef4awtONXwdCvFUUs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":596886},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24 || ^26"},"gitHead":"1cf6767d007afc1ecdf699c2a77591eee3390a40","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.build.json","clean":"rm -rf dist tsconfig.tsbuildinfo tsconfig.build.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.build.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Every IAuthProvider for SAP ABAP ADT: the credentials a process delegates to, and the token providers behind them","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^3.0.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^1.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_5.0.1_1790745202346_0.7692838014852017","host":"s3://npm-registry-packages-npm-production"}},"5.1.0":{"name":"@mcp-abap-adt/auth-providers","version":"5.1.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@5.1.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"c6d0a4ece8b66b8b9ce33fb5f2586d602784d37c","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-5.1.0.tgz","fileCount":176,"integrity":"sha512-u1LEcm/vKoXBqTTF7V5JlT5p0vO77nxH+0dkqcYLND87XFHTu3ZjB5bK3fHVuyc2WkxrL1dF+uHkc430Pg9bMQ==","signatures":[{"sig":"MEQCIDQOPYr4KMl5nHbMuD3EH4rKpowgMI4WB8zNtGUaxIJpAiAf/rB2VAThSauU5LhpHCfPw/dZ/uNmiVflBKBMkwMs5A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIAXTHSQwZ68xKyUMaddjyIM73yMNJRCHf1D0JlCTFEuXAiEAi1YMD0bIUm4JyOXF9GbFsMaDECjrpCqCmcKuzu5Fpfs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":606230},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24 || ^26"},"gitHead":"b4b4248e3fbb9f199bc2751937580f657adb89cd","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.build.json","clean":"rm -rf dist tsconfig.tsbuildinfo tsconfig.build.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.build.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Every IAuthProvider for SAP ABAP ADT: the credentials a process delegates to, and the token providers behind them","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^3.0.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_5.1.0_1790858646510_0.024963912075593342","host":"s3://npm-registry-packages-npm-production"}},"5.2.0":{"name":"@mcp-abap-adt/auth-providers","version":"5.2.0","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","_id":"@mcp-abap-adt/auth-providers@5.2.0","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"d54e21e74067f741a50e46c56cc0f0222005dfcf","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-5.2.0.tgz","fileCount":176,"integrity":"sha512-vc4TxzuAZTP0MYXl0fY3KP8qSmu98me+tZ6a0hD+ECzFFc1MFlHtUROQr2SXjEPspYBMNnBw7ljtu9ZOjRBhWQ==","signatures":[{"sig":"MEUCIQCxMT12Okyh6MarvnKuy4iKeE3A8LqbUJNHjSc4lNv+vwIgDkbWUX3xY+3Z4qCu1N+UhBq+RbkWzmjrWcVnutmhsBY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQC4wj131V0pYkrHed46NmoYUE0L2Ih+y5MZFd1CI2q9UgIge4ZG49sjNry4aeC8dtUGK17V/mRaIirVF+Bnvay8kbg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":606910},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":"^22 || ^24 || ^26"},"gitHead":"5a44d08544fa8336cd9e6138d1b9c13789c4a5c0","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.build.json","clean":"rm -rf dist tsconfig.tsbuildinfo tsconfig.build.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.build.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Every IAuthProvider for SAP ABAP ADT: the credentials a process delegates to, and the token providers behind them","directories":{},"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^3.0.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^1.2.1"},"_npmOperationalInternal":{"tmp":"tmp/auth-providers_5.2.0_1790926085230_0.8244896801558264","host":"s3://npm-registry-packages-npm-production"}},"5.2.1":{"_id":"@mcp-abap-adt/auth-providers@5.2.1","bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"dist":{"shasum":"56a041acac6e8c43bd21fca07284e93c48cd3192","tarball":"https://registry.npmjs.org/@mcp-abap-adt/auth-providers/-/auth-providers-5.2.1.tgz","fileCount":176,"integrity":"sha512-+A3mhIS25ivsR2NIsFds//q09e1AvlE4/y/Mmlu2MVck3bGfWWDxOTLBCAnM2RX+8SWgr1j1rcLa7gTpGkK5sA==","signatures":[{"sig":"MEUCIQCAHm7AXVRW/uiW0iR3i86U7M3sSBaXPi5J/NUA4E/XZwIgKkfNFAIRZUguCPpF0LyGmFf1cveWwMf3tMvbaZjz+JE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGYKWWe/qFBO0kIkOg0AyWahj5m/PVaYfns3fKNGvKLrAiEArCSzZI4qNkrl96yr6PsmkFF2N1P5yQj4U7Brr285Lrc="}],"unpackedSize":608331},"main":"dist/index.js","name":"@mcp-abap-adt/auth-providers","types":"dist/index.d.ts","author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"engines":{"node":"^22 || ^24 || ^26"},"gitHead":"6833bc8458eab4ce98c7eaa471087a9e8055c221","license":"LGPL-3.0-only","scripts":{"lint":"npx biome check --write src","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"npm run --silent clean && npx biome check src --diagnostic-level=error && npx tsc -p tsconfig.build.json","clean":"rm -rf dist tsconfig.tsbuildinfo tsconfig.build.tsbuildinfo","chrono":"./tools/version-stats.sh","format":"npx biome format --write src","stand:up":"tests/stand/up.sh","build:fast":"npx tsc -p tsconfig.build.json","lint:check":"npx biome check src","stand:down":"tests/stand/down.sh","test:check":"npx tsc --noEmit","test:stand":"tests/stand/run.sh","test:xsuaa":"tests/xsuaa/run.sh","prepublishOnly":"npm run build"},"version":"5.2.1","_npmUser":{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"},"homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"_npmVersion":"11.19.0","description":"Every IAuthProvider for SAP ABAP ADT: the credentials a process delegates to, and the token providers behind them","directories":{},"maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"_nodeVersion":"26.7.0","dependencies":{"open":"^11.0.0","axios":"^1.13.5","express":"^5.1.0","xml-crypto":"^6.1.2","@xmldom/xmldom":"^0.9.12","@mcp-abap-adt/interfaces-auth":"^3.0.0","@mcp-abap-adt/interfaces-utils":"^1.1.0","@mcp-abap-adt/interfaces-auth-sap":"^2.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.2.0","pino":"^10.3.1","js-yaml":"^4.1.1","ts-jest":"^29.2.5","jest-util":"^30.2.0","typescript":"^5.9.2","@types/jest":"^30.0.0","@types/node":"^25.2.3","pino-pretty":"^13.1.3","@jest/globals":"^30.2.0","@biomejs/biome":"^2.3.14","@types/express":"^5.0.5","@types/js-yaml":"^4.0.9","@mcp-abap-adt/logger":"^0.4.0","@mcp-abap-adt/auth-mocks":"^0.3.0","@mcp-abap-adt/auth-stores":"^3.1.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/auth-providers_5.2.1_1790949198824_0.7572332481272661"}}},"time":{"created":"2025-12-04T00:26:57.518Z","modified":"2026-10-02T13:53:19.106Z","0.1.0":"2025-12-04T00:26:57.778Z","0.1.1":"2025-12-04T17:57:05.813Z","0.1.2":"2025-12-05T11:16:13.808Z","0.1.3":"2025-12-08T06:12:25.349Z","0.1.4":"2025-12-08T17:02:18.130Z","0.1.5":"2025-12-12T20:12:28.290Z","0.2.0":"2025-12-19T14:38:40.724Z","0.2.1":"2025-12-20T15:37:47.018Z","0.2.2":"2025-12-20T17:45:44.914Z","0.2.3":"2025-12-21T08:31:09.893Z","0.2.4":"2025-12-21T14:51:13.486Z","0.2.5":"2025-12-22T12:58:53.935Z","0.2.6":"2025-12-23T16:45:33.534Z","0.2.7":"2025-12-24T19:48:46.410Z","0.2.8":"2025-12-24T23:14:13.399Z","0.2.9":"2025-12-25T07:32:59.928Z","0.2.10":"2025-12-25T08:00:36.477Z","1.0.0":"2026-02-10T20:00:57.067Z","1.0.1":"2026-02-10T21:32:29.653Z","1.0.2":"2026-02-11T08:28:18.623Z","1.0.3":"2026-02-11T17:05:53.814Z","1.0.4":"2026-02-11T17:42:07.433Z","1.0.5":"2026-02-12T06:08:33.737Z","1.1.0":"2026-06-02T12:25:22.965Z","1.2.0":"2026-07-28T20:29:03.886Z","2.0.0":"2026-08-01T11:02:47.574Z","2.2.0":"2026-09-23T20:56:10.109Z","2.2.1":"2026-09-23T21:25:24.589Z","2.2.2":"2026-09-24T07:42:53.358Z","3.0.0":"2026-09-24T19:56:04.288Z","4.0.0":"2026-09-25T12:55:06.319Z","4.1.0":"2026-09-26T06:28:18.276Z","4.1.2":"2026-09-26T11:29:11.098Z","4.1.3":"2026-09-26T12:26:01.683Z","4.2.0":"2026-09-26T13:19:13.477Z","4.2.1":"2026-09-27T16:23:01.347Z","5.0.0":"2026-09-29T23:11:00.584Z","5.0.1":"2026-09-30T05:13:22.437Z","5.1.0":"2026-10-01T12:44:06.609Z","5.2.0":"2026-10-02T07:28:05.372Z","5.2.1":"2026-10-02T13:53:18.947Z"},"bugs":{"url":"https://github.com/fr0ster/mcp-abap-adt-auth-providers/issues"},"author":{"name":"Oleksii Kyslytsia","email":"oleksij.kyslytsja@gmail.com"},"license":"LGPL-3.0-only","homepage":"https://github.com/fr0ster/mcp-abap-adt-auth-providers#readme","keywords":["abap","sap","adt","jwt","authentication","token","provider","authorization_code","client_credentials","mcp","abap-adt"],"repository":{"url":"git+https://github.com/fr0ster/mcp-abap-adt-auth-providers.git","type":"git"},"description":"Every IAuthProvider for SAP ABAP ADT: the credentials a process delegates to, and the token providers behind them","maintainers":[{"name":"fr0ster","email":"oleksij.kyslytsja@gmail.com"}],"readme":"# @mcp-abap-adt/auth-providers\n[![Stand With Ukraine](https://raw.githubusercontent.com/vshymanskyy/StandWithUkraine/main/badges/StandWithUkraine.svg)](https://stand-with-ukraine.pp.ua)\n\nEvery implementation of `IAuthProvider` for SAP ABAP ADT: the credential a\nprocess delegates to, and the token providers behind it.\n\nToken providers, the Basic/Certificate/SAML/Token credentials and passwordless\nSNC logon are each an `IAuthProvider` the process takes as it is — whether it\nis handed over directly to a connection, or through\n`@mcp-abap-adt/auth-broker` for the stateful token API\n(`getTokens()`/`refreshTokens()`).\n\n## Migrating to 5.0.0 — a migration, not an update\n\n5.0.0 is not an incremental release. Every provider here now implements\n`IAuthProvider` (`@mcp-abap-adt/interfaces-auth` 3.0.0) and can be handed to\nthe process with no wrapper and no check of what it is — which is what a\nconsumer **migrates** to, building its providers from this package and\nhanding them to a `@mcp-abap-adt/connection` **10.0.0** process, rather than\nupdating in place; 9.x speaks the old, narrower `IAuthProvider`.\n\n- **Credentials come from here, not from `@mcp-abap-adt/connection`.**\n  `BasicAuthProvider`, `CertificateAuthProvider`, `SamlAuthProvider`,\n  `TokenAuthProvider` and `FileCertificateMaterialLoader` moved into this\n  package (`src/credentials/`); `connection` 10.0.0 removes its own copies.\n  Import them from `@mcp-abap-adt/auth-providers` instead.\n- **A token provider is handed to the process as it is.**\n  `BaseTokenProvider implements IRefreshableTokenProvider, IAuthProvider`, so\n  every token provider — `AuthorizationCodeProvider`, `ClientCredentialsProvider`,\n  `OidcBrowserProvider`, `OidcDeviceFlowProvider`, `OidcPasswordProvider`,\n  `OidcTokenExchangeProvider`, `Saml2BearerProvider`, `Saml2PureProvider`,\n  `UaaPasscodeProvider` — **is** an `IAuthProvider`, with no `TokenAuthProvider`\n  wrapper around it. The broker's token API (`getTokens()` / `refreshTokens()`)\n  is unchanged.\n- **A store that persisted after `getTokens()` passes `onTokens` instead.**\n  Every token provider's config takes an optional\n  `onTokens?: (result: ITokenResult) => Promise<void>`, called after every\n  *new* token — a login or a refresh, never a cache hit — and awaited before\n  the provider answers. It is best effort: a failing `onTokens` is logged (its\n  class name only, since it holds the tokens) and does not fail the\n  authentication.\n- **Nothing is defaulted any more.** A provider that used to build its own\n  strategy, SAML validator, replay store or device-code output now takes it\n  explicitly in its constructor — or the consumer calls the named factory:\n  `AuthorizationCodeProvider.inBrowser`, `OidcBrowserProvider.inBrowser`,\n  `Saml2PureProvider.inBrowser`, `Saml2BearerProvider.inBrowser`,\n  `UaaPasscodeProvider.fromTerminal`, `OidcDeviceFlowProvider.toConsole`,\n  `CertificateAuthProvider.fromFiles`, `SncLogonProvider.forSecureLoginClient`.\n  Omitting `authorization` (or, for the SAML providers, `assertionValidator`)\n  no longer compiles.\n- **SAML trust configuration moved.** `idpCertificates`, `clockSkewMs` and\n  `assertionReplayStore` are no longer fields of `Saml2BearerProviderConfig` /\n  `Saml2PureProviderConfig`; both now take `assertionValidator:\n  IAssertionValidator` directly (still required, together with `idpEntityId`\n  for a shipped validator). Build one yourself with\n  `createSignedResponseValidator` / `createSignedAssertionValidator`, or call\n  `Saml2PureProvider.inBrowser(config, trust)` /\n  `Saml2BearerProvider.inBrowser(config, trust)` with a `SamlTrust`\n  (`{ idpCertificates, clockSkewMs?, replayStore? }`) — the recipe builds the\n  shipped validator and defaults `replayStore` to `defaultReplayStore`.\n- **`ShippedValidatorOptions.replayStore` is required.** A direct call to\n  `createSignedResponseValidator` / `createSignedAssertionValidator` must now\n  pass one — `defaultReplayStore`, or your own.\n- **Manual strategies take `timeoutMs` and can be disposed.**\n  `manualPasteStrategy`, `manualSamlResponseStrategy` and\n  `manualPasscodeStrategy` accept `timeoutMs?: number`; on expiry, or when\n  `dispose()` is called, the pending read is abandoned with a\n  `BrowserAuthError` and the terminal `readline` it opened is closed —\n  `dispose()` ends every concurrent `authorize()`, and resolves once all\n  have settled. `read`\n  is now `(prompt: string, signal: AbortSignal) => Promise<string>` — the\n  signal aborts on timeout or dispose, and a custom `read` that ignores it\n  still loses the race.\n- **Needs `@mcp-abap-adt/connection` 10.0.0.**\n\n## Passwordless RFC logon (SNC)\n\n`SncLogonProvider` logs an on-premise system on over `RfcTransport` with no\npassword, through an installed SNC product — typically the SAP Secure Login\nClient, holding a certificate from SAP Secure Login Service or Kerberos.\nMeasured 2026-09-29 against an on-premise system (Windows, Secure Login\nClient 3.0.3): the SNC logon, discovery, reads and LOCK/UNLOCK all succeeded\nover `RfcTransport`, each RFC conversation its own SNC logon at roughly\n1–1.5 s. See [docs/passwordless-sso.md](docs/passwordless-sso.md) for the\nHTTP alternatives, which remain undecided.\n\n**Prerequisites:** the SNC product is installed and can log on to the profile\nused for SAP applications (it need not be running beforehand — see the probe\nrule below); the ABAP system accepts SNC for RFC and maps the\ncertificate's SNC name to a user; and, for the `RfcTransport` wire itself, the\nmachine has the SAP NW RFC SDK and `@mcp-abap-adt/sap-rfc-lite` installed.\nThis package itself depends on neither — it produces logon parameters and\nloads nothing.\n\nThe usual choice:\n\n```typescript\nimport { SncLogonProvider } from '@mcp-abap-adt/auth-providers';\n\nconst provider = SncLogonProvider.forSecureLoginClient({\n  partnerName: 'p:CN=<system SNC name>', // the ABAP system's SNC name\n});\n```\n\n`forSecureLoginClient` assembles `nodeSncSystem()` (the machine seam),\n`DefaultSncLibraryLocator(system, sncLib)` and `[SecureLoginClientProbe(system)]`\n— \"this machine, library discovery, the Secure Login Client probe\". `qop`\ndefaults to `'9'` (maximum, one of `'1' | '2' | '3' | '8' | '9'`), and\n`myName` is sent only when set.\n\nThe explicit assembly, for a different SNC product, or a locator/probe of\nyour own (no implicit defaults — a constructor takes every collaborator):\n\n```typescript\nimport {\n  SncLogonProvider,\n  DefaultSncLibraryLocator,\n  SecureLoginClientProbe,\n  nodeSncSystem,\n} from '@mcp-abap-adt/auth-providers';\n\nconst system = nodeSncSystem();\nconst provider = new SncLogonProvider({\n  partnerName: 'p:CN=<system SNC name>',\n  locator: new DefaultSncLibraryLocator(system /*, sncLib */),\n  probes: [new SecureLoginClientProbe(system)], // [] to name no product\n});\n```\n\n**Discovery order and skip rule.** With no explicit `sncLib`,\n`DefaultSncLibraryLocator` tries, in order: the environment variable\n`SNC_LIB_64` (on a 64-bit process), `SNC_LIB`, the Windows registry\n`HKLM\\Software\\SAP\\SecureLogin\\InstallPath64` (`InstallPath32` on a 32-bit\nprocess) plus `lib\\sapcrypto.dll`, then the macOS bundle `/Applications/Secure\nLogin Client.app/Contents/MacOS/lib/libsapcrypto.dylib`. An unusable\ncandidate — missing, not a recognised library, or built for the wrong\narchitecture — is **skipped**, its reason kept, rather than failing the whole\nsearch; empty or whitespace environment variables count as unset. Nothing\nusable → `prepare()` is Oops listing every candidate tried, each as its source,\nits path and its reason, e.g. \"no usable SNC library was found: SNC_LIB\n`<path>` (wrong architecture); registry `<path>` (missing)\" — the source is one\nof `SNC_LIB_64`, `SNC_LIB`, `registry`, `macOS bundle`, and the reason one of\n`missing`, `not a library`, `wrong architecture`; no error message is ever\npart of it, and it needs no logger. An **explicit** `sncLib` is the only\ncandidate: unusable, and the Oops names that one — \"no usable SNC library was\nfound: sncLib `<path>` (missing)\" — with no fallback to automatic discovery.\nThe hint is always \"set sncLib to the SNC (GSS) library of your SNC product\".\nArchitecture comes from the\nfile header — PE `Machine`; Mach-O thin and universal (`FAT_MAGIC` /\n`FAT_MAGIC_64`); ELF `e_machine` — because the trap this guards against is\nmeasured, not theoretical: the Secure Login Client installer sets the\nmachine-wide `SNC_LIB` to its x86 library, and a 64-bit Node process needs the\nx64 one the registry points at.\n\n**The probe rule — the product is named, not checked.** A probe\n(`ISncProductProbe { product; appliesTo(libraryPath) }`) only says which\nproduct is behind the library, so that `rejected()` can say what to do.\n`SecureLoginClientProbe` applies to a library inside the Secure Login\nClient's own installation (the registry's install paths on Windows, matched\ncase-insensitively; the app bundle on macOS); any other SNC library\n(`gsskrb5.dll`, another vendor's) has no product named. `prepare()` only\nresolves the library and notes which probe applies — nothing about the\nproduct is checked before logon, not that it runs, not that a profile is\nlogged on. `prepare()` is therefore Ok with the client not running. Measured\n2026-09-29 (Windows, Secure Login Client 3.0.3): with the client exited, the\nRFC open through its `sapcrypto.dll` **started the client**, which logged on —\nsilently through the identity provider's SSO, or through its logon window. A\n\"not running\" refusal would have stopped logons that succeed. What follows\nfor a consumer: **an RFC open can wait on the client's logon window** until\nthe user answers it. Only the shipped `SecureLoginClientProbe` (recognised by\nclass) yields the Secure Login Client hint; a probe of your own names its\nproduct in the log, never in a refusal.\n\n**The two explained failures**, from `rejected()` — the RFC SDK reports both\nas a generic communication error, so the cause is found by searching the GSS\nerror text (never returned; only fixed wording and an allowlisted key go out):\n\n- **`A2200019`** — reason \"the SNC library has no credential to present\n  (A2200019)\"; hint \"log on in the Secure Login Client, to the profile used\n  for SAP applications\" when the Secure Login Client probe applied, otherwise\n  \"make sure the SNC product behind `<library>` is logged on\". Measured\n  2026-09-29: with the client logged out, closing its logon window failed the\n  RFC open with `GSS-API(min): A2200019:Operation aborted by user or\n  application`, and `rejected()` answered with this reason.\n- **`SNCERR_INIT`** (or \"gssapi library invalid/missing\") — reason \"the RFC\n  SDK could not initialise `<library>` as its SNC library (SNCERR_INIT)\", no\n  hint — usually the architecture mismatch above, if a mismatched library\n  somehow reached this point.\n- anything else — reason \"SNC logon refused\", plus the SDK's error key in\n  parentheses when it is on the RFC-key allowlist (`RFC_LOGON_FAILURE`,\n  `RFC_COMMUNICATION_FAILURE`, …) — never the underlying message or object.\n\n## Installation\n\n```bash\nnpm install @mcp-abap-adt/auth-providers\n```\n\n## Overview\n\nEvery provider here is an `IAuthProvider` (`@mcp-abap-adt/interfaces-auth`\n3.0.0) — `prepare()`, `establish()`, `authorize()`, `rejected()`, each answering\nan `AuthOutcome` and never throwing — handed to the process as it is:\n\n```typescript\nimport { AuthorizationCodeProvider } from '@mcp-abap-adt/auth-providers';\n\nconst provider = AuthorizationCodeProvider.inBrowser({\n  uaaUrl: 'https://...',\n  clientId: '...',\n  clientSecret: '...',\n});\n// A connection 10.0.0 process calls prepare() on connect, authorize() per\n// request, and rejected() on a 401: one renewal — a refresh, else one login.\n```\n\n### What `rejected()` answers\n\nA provider blames its credential — and a token provider renews — only when the\nrejection says the credential was refused: status `401`, or the RFC SDK's\n`RFC_LOGON_FAILURE`. Anything else is answered with a neutral refusal that\nnames only the status or the SDK key, and nothing is renewed:\n\n| The rejection | Basic, certificate, SAML cookies, fixed token | Token providers, `TokenAuthProvider.from` |\n|---|---|---|\n| `401`, `RFC_LOGON_FAILURE` | their own refusal (\"the user or password was refused\", …) | one renewal; Ok only if the credential changed |\n| `403` | \"the credential was accepted, but the user is not authorized (403)\" | the same, no renewal |\n| `3xx` | \"the system redirected instead of accepting the credential (3xx)\" | the same, no renewal |\n| `5xx` | \"the system failed (5xx), not the credential\" | the same, no renewal |\n| any other status | \"the system answered N, which is not a credential refusal\" | the same, no renewal |\n| another RFC key | \"the RFC logon failed (KEY), not as a credential refusal\" | the same, no renewal |\n| neither a status nor a known key | \"the logon failed (unknown error)\" | one renewal — the rejection cannot tell |\n\n`SncLogonProvider` explains a GSS code in the error first (`A2200019`,\n`SNCERR_INIT`) — the SDK reports SNC logon failures as a communication\nfailure — and otherwise answers the same way.\n\nThe token providers also implement `IRefreshableTokenProvider` —\n`ITokenProvider` plus `refreshTokens()` — for the broker's token API:\n\n- **ClientCredentialsProvider** — `client_credentials`, no user interaction\n- **AuthorizationCodeProvider** — UAA/XSUAA authorization code, through a browser\n- **UaaPasscodeProvider** — UAA/XSUAA one-time passcode from `/passcode`, the\n  login `cf login --sso` uses: SSO without a browser on this machine\n- **OidcBrowserProvider** — OIDC authorization code with PKCE\n- **OidcDeviceFlowProvider** — OAuth 2.0 device authorization grant (RFC 8628)\n- **OidcPasswordProvider**, **OidcTokenExchangeProvider** — password grant and\n  token exchange (RFC 8693)\n- **Saml2BearerProvider** — a SAML assertion exchanged for an OAuth2 token\n  (RFC 7522)\n- **Saml2PureProvider** — a SAML assertion exchanged for session cookies\n\nProviders are configured via constructor; `getTokens()` takes no parameters and handles refresh/login internally. `refreshTokens()` obtains a new token even while the cached one looks valid — what a caller holding a 401 needs.\n\nA token is only half of it: whether ADT accepts it depends on the XSUAA client,\nthe trust and the user configured on the SAP side. What each provider needs\nthere, and which are usable for ADT at all, is in\n[docs/btp-setup.md](docs/btp-setup.md).\nLogging on without a password — SAP GUI's SNC single sign-on and its HTTP\nequivalents, X.509 client certificates and SPNego — is in\n[docs/passwordless-sso.md](docs/passwordless-sso.md).\n\nSince 2.0.0 an interactive login is conducted by an **authorization strategy**\n(`IAuthorizationStrategy` from `@mcp-abap-adt/interfaces-auth`) passed as\n`authorization`. The provider owns what it can compute — the authorization URL\nand the token exchange; everything between them (reaching the URL, receiving\nwhat comes back, the port, the timeout) belongs to the strategy, which a\nconsumer may replace wholesale. See\n[Choosing an authorization strategy](#choosing-an-authorization-strategy).\n\nSince 4.0.0 both SAML providers **validate the assertion before trusting it** —\nits signature, issuer, audience, recipient, time window, the request it answers,\nand whether it has been seen before — and must therefore be told which identity\nprovider to trust. This is a breaking change: a 3.x SAML configuration fails at\nconstruction. See [SAML assertion validation](#saml-assertion-validation).\n\nIf you are on an earlier version, see\n[Upgrading from 4.0 to 4.1](#upgrading-from-40-to-41),\n[Migrating from 3.x to 4.0](#migrating-from-3x-to-40),\n[Migrating from 2.x to 3.0](#migrating-from-2x-to-30) and\n[Migrating from 1.x to 2.0](#migrating-from-1x-to-20).\n\n## Responsibilities and Design Principles\n\n### Core Development Principle\n\n**Interface-Only Communication**: This package follows a fundamental development principle: **all interactions with external dependencies happen ONLY through interfaces**. The code knows **NOTHING beyond what is defined in the interfaces**.\n\nThis means:\n- Does not know about concrete implementation classes from other packages\n- Does not know about internal data structures or methods not defined in interfaces\n- Does not make assumptions about implementation behavior beyond interface contracts\n- Does not access properties or methods not explicitly defined in interfaces\n\nThis principle ensures:\n- **Loose coupling**: Providers are decoupled from concrete implementations in other packages\n- **Flexibility**: New implementations can be added without modifying providers\n- **Testability**: Easy to mock dependencies for testing\n- **Maintainability**: Changes to implementations don't affect providers\n\n### Package Responsibilities\n\nThis package is responsible for:\n\n1. **Implementing token provider interface**: Provides concrete implementations of `ITokenProvider` interface defined in `@mcp-abap-adt/interfaces-auth`\n2. **Token acquisition**: Handles OAuth2 flows (browser-based, refresh token, client credentials) to obtain JWT tokens\n3. **Token validation**: Validates JWT locally by checking exp claim (no HTTP requests)\n4. **OAuth2 flows**: Manages browser-based OAuth2 authorization code flow and refresh token flow\n5. **SAML assertion validation**: Verifies a SAML assertion — signature, issuer, audience, recipient, time window, request ID, replay — before either SAML provider uses it\n\n#### What This Package Does\n\n- **Implements ITokenProvider**: Provides concrete implementations (`AuthorizationCodeProvider`, `ClientCredentialsProvider`)\n- **Handles OAuth2 flows**: Browser-based OAuth2, refresh token, and client credentials grant types\n- **Obtains tokens**: Makes HTTP requests to UAA endpoints to obtain JWT tokens\n- **Validates tokens**: Validates JWT locally by checking exp claim (no HTTP requests)\n- **Returns tokens**: Returns `ITokenResult` with `authorizationToken` and optional `refreshToken`\n- **Validates SAML assertions**: Ships two validators (`createSignedResponseValidator`, `createSignedAssertionValidator`) and an in-memory replay store (`defaultReplayStore`); each SAML provider takes its validator as `assertionValidator` — built by the `inBrowser(config, trust)` factory, or supplied by the consumer, who may also supply its own `IAssertionValidator` or `IAssertionReplayStore`\n\n#### What This Package Does NOT Do\n\n- **Does NOT store tokens**: Token storage is handled by `@mcp-abap-adt/auth-stores`\n- **Does NOT orchestrate authentication**: Token lifecycle management is handled by `@mcp-abap-adt/auth-broker`\n- **Does NOT know about service keys**: Service key loading is handled by stores\n- **Does NOT manage sessions**: Session management is handled by stores\n- **Does NOT return `serviceUrl` if unknown**: Providers may not return `serviceUrl` because they only handle token acquisition, not connection configuration\n- **Does NOT fetch identity provider metadata**: The certificates and entity ID a SAML assertion is checked against come from configuration; reading them from a file or a metadata URL is the consumer's job\n\n### External Dependencies\n\nThis package interacts with external packages **ONLY through interfaces**:\n\n- **`@mcp-abap-adt/auth-broker`**: Uses interfaces (`ITokenProvider`, `IAuthorizationConfig`) - does not know about `AuthBroker` implementation\n- **`@mcp-abap-adt/logger`**: Uses `Logger` interface for logging - does not know about concrete logger implementation\n- **`@mcp-abap-adt/connection`**: Uses connection utilities for token validation - interacts through well-defined functions\n- **No direct dependencies on stores**: All interactions with stores happen through interfaces passed by consumers\n\n## Usage\n\n### Basic Usage\n\n```typescript\nimport { AuthBroker } from '@mcp-abap-adt/auth-broker';\nimport {\n  AuthorizationCodeProvider,\n  ClientCredentialsProvider,\n  browserCallbackStrategy,\n} from '@mcp-abap-adt/auth-providers';\n\n// User token via authorization_code (browser flow)\nconst authCodeBroker = new AuthBroker({\n  tokenProvider: new AuthorizationCodeProvider({\n    uaaUrl: 'https://...',\n    clientId: '...',\n    clientSecret: '...',\n    authorization: browserCallbackStrategy({ browser: 'system' }),\n  }),\n});\n\n// Service token via client_credentials (no browser)\nconst clientCredsBroker = new AuthBroker({\n  tokenProvider: new ClientCredentialsProvider({\n    uaaUrl: 'https://...',\n    clientId: '...',\n    clientSecret: '...',\n  }),\n}, 'none');\n```\n\n### Choosing an authorization strategy\n\n`authorization` decides how an interactive login is conducted. Omit it and the\nprovider builds the callback strategy for its own flow, on the default port —\nwhich is convenient, and is also the only case where the default port applies\nwithout you having chosen it. Every shipped strategy is a plain function\nreturning `IAuthorizationStrategy`, so a consumer can pass its own instead.\n\n| Strategy | For | What it does |\n|---|---|---|\n| `browserCallbackStrategy(opts)` | `AuthorizationCodeProvider` | Binds a local callback server, opens the URL, waits for `?code=` |\n| `oidcCallbackStrategy(opts)` | `OidcBrowserProvider` | The same, yielding `{ code, state }` |\n| `samlCallbackStrategy(opts)` | `Saml2BearerProvider`, `Saml2PureProvider` | The same, receiving a posted `SAMLResponse` |\n| `manualPasteStrategy({ redirectUri, read })` | code flows | Shows the URL, reads the pasted code (stdin by default) |\n| `manualSamlResponseStrategy({ redirectUri, read })` | SAML flows | Shows the URL, reads the pasted `SAMLResponse` |\n| `externalCodeStrategy({ redirectUri, provide })` | either | Hands the assembled URL to your function, takes back the payload |\n| `staticCodeStrategy({ redirectUri, payload })` | either | You already hold the payload; the URL is never built |\n| your own | any | Implement `IAuthorizationStrategy<TResult>` and pass it |\n\nOptions common to the three callback strategies:\n\n| Option | Default | Meaning |\n|---|---|---|\n| `port` | `61001` (`DEFAULT_CALLBACK_PORT`) | Port to bind. `0` binds an ephemeral one — usable only where the identity provider accepts a loopback redirect on any port, never where a fixed redirect URI is registered |\n| `timeoutMs` | `30000` (`DEFAULT_LOGIN_TIMEOUT_MS`) | How long the login may wait for its callback |\n| `browser` | `'none'` | `'none'` / `'headless'` print the URL; `'system'`, `'auto'`, `'chrome'`, `'edge'`, `'firefox'` open it |\n| `callbackServer` | the one this package ships | Your own `CallbackServerFactory`, to reuse a server you already run |\n| `openUrl` | the built-in launcher | Receives `(url, browser, redirectUri)` |\n| `remoteHint` | the paste hint, only for the shipped UAA transport | Extra guidance printed in `'none'` / `'headless'` mode |\n| `signal` | — | `AbortSignal` cancelling the login |\n\nNote the `browser` default: **`'none'`, so nothing is opened unless you ask for\nit.** The URL is always shown, even with no logger — it falls back to `stderr`,\nnever stdout, so an MCP/LSP stdio transport is not corrupted. (1.x behaved the\nsame way; the 1.x README claiming `system` was the default was wrong.)\n\nThe three `CallbackServerFactory` implementations are exported too —\n`withBrowserCallbackServer`, `withOidcCallbackServer`, `withSamlCallbackServer`\n— so a consumer can keep the transport and replace everything around it, or the\nreverse.\n\nFor the three shipped flows, passing `callbackServer` to a ready constructor is\nthe way to substitute a transport. The `BrowserCallbackStrategy` class behind\nthem is exported as well, for the case the constructors cannot express: a\nreceiver whose payload is none of the three shapes those flows deliver. Its\noptions are the same, except `callbackServer` is required — there is no default\ntransport to fall back on when the payload type is your own.\n\n```typescript\nimport { BrowserCallbackStrategy } from '@mcp-abap-adt/auth-providers';\n\nconst strategy = new BrowserCallbackStrategy<MyPayload>({\n  callbackServer: withMyOwnCallbackServer, // CallbackServerFactory<MyPayload>\n  port: 61001,\n  timeoutMs: 30000,\n});\n```\n\n#### Bringing your own\n\n```typescript\nimport type { IAuthorizationStrategy } from '@mcp-abap-adt/interfaces-auth';\n\nconst fromOurPortal: IAuthorizationStrategy<string> = {\n  async authorize(request) {\n    const redirectUri = 'https://portal.internal/oauth/callback';\n    const url = await request.buildAuthorizationUrl(redirectUri);\n    // The redirect URI you return is the one sent to the token endpoint.\n    return { payload: await ourPortal.login(url), redirectUri };\n  },\n  async dispose() { await ourPortal.close(); },\n};\n```\n\n`dispose` is optional, and whoever constructs a strategy disposes of it: a\nstrategy you pass in is yours to dispose, one the provider defaulted to is\ndisposed by the provider.\n\n#### Manual paste over a callback server\n\nWith `browserCallbackStrategy` (the UAA transport), login can complete through\neither of **two** channels — whichever finishes first wins:\n\n1. **Automatic callback** — `GET /callback?code=...` on the bound redirect URI.\n   Works when the browser is on the same machine as the process.\n2. **Paste form** — open `http://<this-host>:<port>/` and paste the code (or the\n   whole redirected URL). Works when the browser is on a *different* machine,\n   since the callback server listens on all interfaces. In `'none'` /\n   `'headless'` mode the strategy prints this address for you — with the real\n   port and the host left for you to fill in, because the process cannot know\n   which of its addresses you can reach.\n\n**The terminal-paste channel is gone.** In 1.x a third channel read the code\nfrom stdin when `process.stdin.isTTY`; `browserCallbackStrategy` has no such\nreader, and this is deliberate rather than an oversight — under an MCP or LSP\nstdio transport stdin carries the protocol, and an authorization library has no\nbusiness consuming it. Reading a pasted code is now a strategy of its own:\n\n```typescript\nimport {\n  AuthorizationCodeProvider,\n  manualPasteStrategy,\n} from '@mcp-abap-adt/auth-providers';\n\nconst provider = new AuthorizationCodeProvider({\n  uaaUrl, clientId, clientSecret,\n  // Binds no socket at all: prints the URL, then reads one line.\n  // Defaults to stdin when it is a TTY — pass `read` to source it anywhere else.\n  authorization: manualPasteStrategy({\n    redirectUri: 'http://localhost:61001/callback',\n  }),\n});\n```\n\n`manualPasteStrategy` reads from stdin only when `process.stdin.isTTY`, and\nthrows a clear error otherwise rather than consuming a protocol stream. Supply\n`read` to take the value from somewhere else entirely — a TUI prompt, an HTTP\nrequest, a file:\n\n```typescript\nauthorization: manualPasteStrategy({\n  redirectUri: 'http://localhost:61001/callback',\n  read: async (prompt) => askInOurUi(prompt),\n})\n```\n\nThe `redirectUri` you give it must be the one the identity provider will\nredirect to; it is also the one sent to the token endpoint. It defaults to\n`http://localhost:61001/callback`.\n\nBoth the paste form and `manualPasteStrategy` accept a bare code, `code=...`,\nor a full redirected URL — whichever you paste, the code is extracted from it.\n\n> The `extractCode(input)` helper behind that leniency is internal; it is not\n> part of the package's exports, contrary to what the 1.1.0–1.2.0 README said.\n\n### SSO Providers\n\nThis package also includes SSO providers for OIDC and SAML2, plus a small factory for DI-friendly creation.\n\nAvailable providers:\n- `OidcBrowserProvider` (authorization code + PKCE)\n- `OidcDeviceFlowProvider`\n- `OidcPasswordProvider`\n- `OidcTokenExchangeProvider`\n- `Saml2BearerProvider` (SAML assertion exchange)\n- `Saml2PureProvider` (returns SAMLResponse as token)\n\nFactory example:\n\n```typescript\nimport { AuthBroker } from '@mcp-abap-adt/auth-broker';\nimport {\n  SsoProviderFactory,\n  oidcCallbackStrategy,\n} from '@mcp-abap-adt/auth-providers';\n\nconst tokenProvider = SsoProviderFactory.create({\n  protocol: 'oidc',\n  flow: 'browser',\n  config: {\n    issuerUrl: 'https://example-idp/.well-known/openid-configuration',\n    clientId: '...',\n    clientSecret: '...',\n    scopes: ['openid', 'profile', 'email'],\n    authorization: oidcCallbackStrategy({ browser: 'system' }),\n  },\n});\n\nconst broker = new AuthBroker({ tokenProvider }, 'none');\n```\n\nOIDC browser example (a code you already hold + explicit endpoints):\n\n```typescript\nimport {\n  OidcBrowserProvider,\n  asOidcResult,\n  staticCodeStrategy,\n} from '@mcp-abap-adt/auth-providers';\n\nconst redirectUri = 'urn:ietf:wg:oauth:2.0:oob';\n\nconst provider = new OidcBrowserProvider({\n  clientId: '...',\n  tokenEndpoint: 'https://issuer/oauth/token',\n  authorizationEndpoint: 'https://issuer/oauth/authorize',\n  authorization: asOidcResult(\n    staticCodeStrategy({ redirectUri, payload: '<paste-code-here>' }),\n  ),\n});\n```\n\n`asOidcResult` is not optional here. `OidcBrowserProvider` takes\n`IAuthorizationStrategy<OidcCallbackResult>`, and the code-producing strategies\n(`staticCodeStrategy`, `externalCodeStrategy`, `manualPasteStrategy`) yield a\n`string`; passing one directly does not type-check. The adapter wraps the code\nas `{ code }` — a value that never travelled through a redirect carries no\n`state` to check — and delegates `dispose`, so wrapping costs nothing in\nlifecycle terms.\n\nThe redirect URI is no longer a provider field: it belongs to the strategy,\nbecause with an ephemeral port nothing knows it until the socket is bound. The\none the strategy reports is the one sent to the token endpoint.\n\nBoth SAML providers validate every assertion before using it, so every SAML\nexample below says whom to trust: an `assertionValidator` built from the\nidentity provider's certificates, and `idpEntityId`. The recipe\n`inBrowser(config, trust)` builds the shipped validator from a `SamlTrust`\n(`{ idpCertificates, clockSkewMs?, replayStore? }`); a constructor takes one\nyou built. See [SAML assertion validation](#saml-assertion-validation) for\nwhat is checked and what else can be configured.\n\nSAML bearer example (UAA or XSUAA — an IdP-initiated assertion):\n\n```typescript\nimport { readFileSync } from 'node:fs';\nimport { AuthBroker } from '@mcp-abap-adt/auth-broker';\nimport type { IAuthorizationStrategy } from '@mcp-abap-adt/interfaces-auth';\nimport {\n  Saml2BearerProvider,\n  createSignedAssertionValidator,\n  defaultReplayStore,\n} from '@mcp-abap-adt/auth-providers';\n\n// The Recipient the assertion names: the URI-binding assertion consumer\n// service in the token endpoint's SAML metadata (UAA's is /oauth/token/alias/…).\nconst acsUrl = 'https://uaa.example.com/oauth/token/alias/uaa.example';\n\n// An IdP-initiated login answers no AuthnRequest, so this strategy never calls\n// request.buildAuthorizationUrl — with idpInitiated: true and no\n// authorizationUrl, the builder refuses before producing a URL, since the only\n// one it could build carries an AuthnRequest. It fetches a fresh assertion on every login;\n// the same assertion presented twice is refused as a replay.\nconst fromSsoProxy: IAuthorizationStrategy<string> = {\n  async authorize() {\n    return { payload: await getSamlResponseFromSsoProxy(), redirectUri: acsUrl };\n  },\n};\n\nconst provider = new Saml2BearerProvider({\n  idpSsoUrl: 'https://idp.example.com/sso',\n  spEntityId: 'uaa.example', // the entityID in that metadata: the Audience\n  acsUrl,\n  uaaUrl: 'https://uaa.example.com',\n  clientId: '...',\n  clientSecret: '...',\n  // Whom to trust: a validator holding the identity provider's signing\n  // certificate, and its entity ID.\n  assertionValidator: createSignedAssertionValidator({\n    idpCertificates: [readFileSync('idp-signing.pem', 'utf8')],\n    replayStore: defaultReplayStore,\n  }),\n  idpEntityId: 'https://idp.example.com/metadata',\n  // UAA and XSUAA refuse an assertion carrying InResponseTo.\n  idpInitiated: true,\n  authorization: fromSsoProxy,\n});\n\nconst broker = new AuthBroker({ tokenProvider: provider }, 'none');\n```\n\n**Who starts the login matters.** An identity provider answering an\n`AuthnRequest` — which is what the provider's own URL carries, and so what every\nshipped strategy that opens or shows that URL sends — puts `InResponseTo` on\nthe assertion's subject confirmation. The saml2-bearer grant of Cloud Foundry UAA and of SAP\nXSUAA refuses any assertion that carries it: there is no request on their side\nto match it against, and UAA's `disableInResponseToCheck` applies to web SSO\nonly. Measured: UAA, with Keycloak as the identity provider, refuses the answer\nto an SP-initiated login with *\"SubjectConfirmationData/@InResponseTo … did not\nmatch the valid value: null\"*, and XSUAA — measured with 3.x, which sent such an\nassertion on — refuses one carrying `InResponseTo` with *\"No subject\nconfirmation methods were met\"*; both accept an IdP-initiated one — started at\nthe IdP, answering no request. (4.0 refuses that case itself, at\n`bearerConfirmation`, before XSUAA sees it.) Against either,\nsupply an IdP-initiated assertion, declare `idpInitiated: true`, and use a\nstrategy that does not call\n`buildAuthorizationUrl`: `staticCodeStrategy`, or your own as above.\n`samlCallbackStrategy`, `manualSamlResponseStrategy` and `externalCodeStrategy`\nall call it, and with `idpInitiated: true` and no `authorizationUrl` the builder\nrefuses: a `ValidationError` (`missingFields: ['authorizationUrl']`) thrown\nbefore any URL is produced, so before a browser opens. (3.0's advice —\n`externalCodeStrategy` whose `provide` ignores the URL — no longer works for\nthat reason.) See\n[Where the expected request ID comes from](#where-the-expected-request-id-comes-from).\n\nThe `redirectUri` your strategy reports is the ACS the assertion is checked\nagainst — its `SubjectConfirmationData/@Recipient` must equal it — so for the\nbearer grant it is the token endpoint's bearer ACS, not a local callback.\n\n**What is sent.** The saml2-bearer grant takes one SAML Assertion,\nbase64url-encoded (RFC 7522 §2.1). A strategy may deliver either that or the\nwhole `SAMLResponse` an identity provider posts, in standard base64 —\n`Saml2BearerProvider` validates what it received, then takes the Assertion out\nof a Response and re-encodes it, copying onto it every namespace declaration it\ninherited — including one used only inside a value such as\n`xsi:type=\"xs:string\"`. The Assertion must carry its own signature: one over the\nResponse alone does not survive the cut, and the token endpoint refuses the\nAssertion — which is why the validator this provider's `inBrowser` recipe\nbuilds is the one that requires the Assertion to be signed. An `EncryptedAssertion` is refused before\nanything is sent.\n\n**Refresh.** When the token endpoint returns a `refresh_token` with the SAML\nbearer exchange, `Saml2BearerProvider` spends it once the access token expires:\na `refresh_token` grant to the same endpoint (`tokenUrl`, or `uaaUrl` +\n`/oauth/token`) with the same client credentials, and no assertion, strategy or\nbrowser involved. Pass a stored one back as `refreshToken` in the config and the\nnext `getTokens()` uses it. If the grant is refused, or no refresh token was\never issued, the provider falls back to a full login through `authorization`.\n\nPure SAML example (cookie-based, SP-initiated):\n\n```typescript\nimport { readFileSync } from 'node:fs';\nimport { AuthBroker } from '@mcp-abap-adt/auth-broker';\nimport {\n  Saml2PureProvider,\n  createSignedResponseValidator,\n  defaultReplayStore,\n  manualSamlResponseStrategy,\n} from '@mcp-abap-adt/auth-providers';\n\nconst acsUrl = 'https://sp.example.com/saml/acs';\n\nconst provider = new Saml2PureProvider({\n  idpSsoUrl: 'https://idp.example.com/sso',\n  spEntityId: 'my-sp-entity',\n  acsUrl,\n  assertionValidator: createSignedResponseValidator({\n    idpCertificates: [readFileSync('idp-signing.pem', 'utf8')],\n    replayStore: defaultReplayStore,\n  }),\n  idpEntityId: 'https://idp.example.com/metadata',\n  // Shows the URL the provider builds — so the response must answer that\n  // request's ID — and reads the pasted SAMLResponse.\n  authorization: manualSamlResponseStrategy({ redirectUri: acsUrl, read: promptUser }),\n  // Convert SAMLResponse to session cookies for SAP (implementation-specific)\n  cookieProvider: async (samlResponse) => {\n    return exchangeSamlForCookies(samlResponse);\n  },\n});\n\nconst broker = new AuthBroker({ tokenProvider: provider }, 'none');\n```\n\n`cookieProvider` receives the payload unchanged, only after it has been\nvalidated, and the session's `expiresAt` is the validated assertion's expiry.\n\n**Stored cookies.** Pass cookies a previous login obtained as `accessToken`,\nwith the `expiresAt` they were obtained with (epoch ms — `onTokens` and\n`getTokens()` report it). Until `expiresAt`, less a one-minute buffer, the\nprovider presents them and runs no login: no strategy, no validator, no\n`cookieProvider`. Past it — or with no `expiresAt`, since cookies carry no\nexpiry of their own — the first `getTokens()` or `authorize()` logs in as\nabove. There is no `refreshToken`: SAML has none, so renewal is a new login.\nSee [Seeding a stored credential](#seeding-a-stored-credential).\n\n**Read that `redirectUri` twice.** A SAML strategy defaults its redirect URI to\n`http://localhost:61001/callback`, and the provider requires the assertion\nconsumer service the IdP posts to be exactly the one the strategy names. If you\ndeclare a real `acsUrl` and leave `redirectUri` off, the login fails with\n*\"SAML acsUrl is … but the authorization strategy is listening on …\"* before\nanything is opened. Declare neither and the default is used for both, which is\nconsistent — and only reachable when the IdP will post to your localhost.\n\nBoth SAML providers now reject at construction when `authorizationUrl` is set\nwithout `acsUrl`:\n\n```\nacsUrl is required when authorizationUrl is set: the ACS inside a pre-built\nSAML request cannot be read, so it must be declared.\n```\n\nThe ACS is buried in a deflated `SAMLRequest` this package did not build and\ncannot read, so it cannot be verified against whatever the strategy binds. 1.x\naccepted the combination and defaulted the ACS to\n`http://localhost:3001/callback` — usually not where the IdP posted. The same\nholds for the request ID: this package cannot read it out of a URL it did not\nbuild, so a pre-built `authorizationUrl` also needs `authnRequestId` — unless\nthe login is declared `idpInitiated`.\n\n### SAML assertion validation\n\nSince 4.0.0, `Saml2BearerProvider` and `Saml2PureProvider` validate the\nassertion a login delivers before anything else happens to it — before the\ntoken exchange, before `cookieProvider`. Until 3.x nothing verified it: the\ncallback checked only that the payload was non-empty, and `Saml2PureProvider`\ntook its session lifetime from a regular expression over the unverified XML.\n\n**Whom to trust is required.** Since 5.0.0 each provider takes its validator\nas `assertionValidator` — a shipped one built from the identity provider's\ncertificates, or your own — and omitting it does not compile. A shipped\nvalidator supplied without `idpEntityId` fails at construction — a\n`ValidationError` whose `missingFields` names it — before any browser opens or\nany request is sent. `inBrowser(config, trust)` is the recipe that builds the\nshipped validator from a `SamlTrust`.\n\n#### Configuration\n\nOn both providers' configuration (`Saml2BearerProviderConfig`, `Saml2PureProviderConfig`):\n\n| Field | Default | Meaning |\n|---|---|---|\n| `assertionValidator` | — | **Required.** An `IAssertionValidator`: `createSignedResponseValidator(…)`, `createSignedAssertionValidator(…)`, or your own. The provider builds none of its own |\n| `idpEntityId` | — | The `Issuer` the assertion must name, passed to the validator as `expectedIssuer`. **Required unless the `assertionValidator` supplied is your own**: a shipped validator refuses every assertion without an expected issuer, so supplying one without `idpEntityId` fails at construction. A custom validator does not need it, and receives it when given |\n| `spEntityId` | — | Your entity ID. The assertion's `AudienceRestriction` must name it — whichever validator is in play |\n| `authnRequestId` | — | The AuthnRequest ID this login answers, when the package did not build the request — see [Where the expected request ID comes from](#where-the-expected-request-id-comes-from) |\n| `idpInitiated` | `false` | Declares that no AuthnRequest was sent, so the assertion must carry no `InResponseTo`. Required for `Saml2BearerProvider` against UAA or XSUAA |\n\nTrust itself — the certificates, the clock skew, the replay store — is not a\nprovider field. It is on the shipped validator's options\n(`ShippedValidatorOptions`), or on the `SamlTrust` the `inBrowser` recipe\ntakes:\n\n| Field | Default | Meaning |\n|---|---|---|\n| `idpCertificates` | — | The identity provider's signing certificates, PEM or bare base64 DER — the form `<X509Certificate>` has in IdP metadata. A list, because providers rotate keys and two are live during a rotation. Each entry is parsed when the validator is built, so a malformed one fails there, not at login |\n| `replayStore` | — on `ShippedValidatorOptions` (required); `defaultReplayStore` in the `inBrowser` recipe | An `IAssertionReplayStore` — see [Replay](#replay) |\n| `clockSkewMs` | `0` | Tolerance for the time checks — see [Clock skew](#clock-skew) |\n\nThe package performs no I/O for any of these: it fetches no metadata and reads\nno file. Reading the certificate is the consumer's job.\n\n#### Choosing a validator\n\nThis is the first decision to make, and **the `inBrowser` recipe chooses\ndifferently per provider**:\n\n| | `createSignedResponseValidator` | `createSignedAssertionValidator` |\n|---|---|---|\n| The signature must cover | the `Response` | the `Assertion` — bare, or inside a Response |\n| Built by `inBrowser` of | `Saml2PureProvider` | `Saml2BearerProvider` |\n| Reads `Status`, `Response/Issuer`, `Destination` | yes — inside the signature | **not at all** |\n| Accepts a bare `saml:Assertion` | no | yes |\n| Checks performed | all twelve below | all but rows 4, 5b and 11 |\n\nBoth take the same options (`ShippedValidatorOptions`) and return the same\ninterface, so switching is one identifier:\n\n```typescript\nimport { readFileSync } from 'node:fs';\nimport {\n  Saml2PureProvider,\n  createSignedAssertionValidator,\n  defaultReplayStore,\n  samlCallbackStrategy,\n} from '@mcp-abap-adt/auth-providers';\n\nconst idpCertificates = [readFileSync('idp-signing.pem', 'utf8')];\n\nconst provider = new Saml2PureProvider({\n  idpSsoUrl: 'https://idp.example.com/sso',\n  spEntityId: 'my-sp-entity',\n  acsUrl: 'https://sp.example.com/saml/acs',\n  // Still required with a shipped validator, which refuses every assertion\n  // without an expected issuer; construction fails without it.\n  idpEntityId: 'https://idp.example.com/metadata',\n  // Our identity provider signs only its assertions.\n  assertionValidator: createSignedAssertionValidator({\n    idpCertificates,\n    clockSkewMs: 30_000,\n    replayStore: defaultReplayStore,\n  }),\n  authorization: samlCallbackStrategy(),\n  cookieProvider: exchangeSamlForCookies,\n});\n```\n\n**`createSignedResponseValidator`** requires the identity provider to sign the\n`Response`. Every field all twelve checks read is then inside the signature, so\nevery check is a control. It is what `Saml2PureProvider.inBrowser` builds because there the\nwhole response is handed on to `cookieProvider`, and `Status` and `Destination`\nmust be inside a signature.\n\n**`createSignedAssertionValidator`** accepts a signature over the `Assertion`,\nand **does not read** `Status`, `Response/Issuer` or `Destination` at all — not\nweakly: with an assertion-only signature those fields sit outside it, where\nanyone able to deliver a response sets them to whatever is expected, and a check\non a field an attacker controls reads in the code and the logs as if something\nhad been verified. It is what `Saml2BearerProvider.inBrowser` builds because the token\nendpoint receives the Assertion alone, taken out of any Response, so the\nAssertion's own signature is what counts there. Configuring the signed-Response\nvalidator on the bearer path would refuse a bare Assertion, and accept responses\nsigned only at the Response level, which the token endpoint then refuses.\n\n**Who needs the second one.** Identity providers that sign only assertions —\nwhich is many. A `Saml2PureProvider` consumer whose IdP does so gets a\n`signedNode` refusal from the recipe's validator, and selects\n`createSignedAssertionValidator` explicitly. What that gives up is the three\nchecks above. It is still sound:\n\n- **`Status`** — a declined login carries no assertion. An identity provider\n  that refuses does not mint one, so flipping `Status` to `Success` leaves an\n  attacker with nothing signed to put beneath it. Success is established by a\n  signed assertion passing every assertion-level check.\n- **`Destination`** — addressing rests on\n  `SubjectConfirmationData/@Recipient`, which is inside the signed assertion and\n  required by check 10.\n- **`Response/Issuer`** — the assertion's own `Issuer`, inside the signature, is\n  checked against `idpEntityId`.\n\nAn identity provider that signs both the Response and the Assertion — Keycloak\ndoes by default — satisfies either validator.\n\n#### What the validators check\n\nIn this order; each refusal is an `AssertionValidationError` whose `check`\nnames the row. Rows marked *(signed-Response only)* are not performed by\n`createSignedAssertionValidator`.\n\n| # | Check | Refused when | `check` |\n|---|---|---|---|\n| 1 | Parses as XML, with no `DOCTYPE`; the document element is `samlp:Response` — or, for the assertion-only validator, a bare `saml:Assertion` | it is not, or it carries a `<!DOCTYPE` declaration | `document` |\n| 1b | Every `ID` attribute in the document is unique | any value appears twice | `duplicateId` |\n| 2 | Every signature is valid against `idpCertificates` — never against a certificate the document carries in its own `KeyInfo` | none, wrong key, content altered after signing, a malformed `Signature` element, no `ds:Reference` or more than one, a reference that is not same-document or names no element by `ID`, or a signature not inside the element it references | `signature` |\n| 3 | The signed node is the node read | the Response carries no direct-child `Assertion`, or more than one; the signature does not cover the element this validator requires — the `Response`, or the bare root `Assertion` or the Response's direct-child `Assertion`; or any SAML 2.0 `Assertion` / `EncryptedAssertion`, or SAML 1.x `Assertion`, lies outside the signed assertion or inside a `ds:Signature` | `signedNode` |\n| 4 | `samlp:Status` *(signed-Response only)* | absent or more than one; its `StatusCode` absent or more than one; the `StatusCode` without a `Value`; or a `Value` other than `…:status:Success` | `status` |\n| 4b | `Assertion/@ID` | absent or empty | `assertionId` |\n| 5 | `Assertion/Issuer` | absent, more than one, empty, not the expected issuer, or no expected issuer was given | `issuer` |\n| 5b | `Response/Issuer` *(signed-Response only; optional)* | present and disagreeing with `Assertion/Issuer`, or present twice — absent is accepted | `issuer` |\n| 6 | `Conditions` | absent, or more than one | `conditions` |\n| 7 | `Conditions/@NotBefore` *(optional)* | present and not a valid `xsd:dateTime`, or in the future beyond `clockSkewMs` — absent is accepted | `notBefore` |\n| 8 | `Conditions/@NotOnOrAfter` | absent, not a valid `xsd:dateTime`, or in the past beyond `clockSkewMs` | `notOnOrAfter` |\n| 9 | `Conditions/AudienceRestriction` | absent, **any one** restriction naming no `Audience` at all, or **any one** failing to name `spEntityId` | `audience` |\n| 10 | One bearer `SubjectConfirmation` | the `Subject` absent or more than one, holding no `SubjectConfirmation`, or no confirmation satisfying every part — see below | `bearerConfirmation` |\n| 11 | `Response/@Destination` *(signed-Response only)* | absent, or not the ACS the response arrived at | `destination` |\n| 12 | Replay | the store has already recorded this `{issuer, ID}` | `replay` |\n\nWhat the table compresses:\n\n- **Every required field is refused when absent**, not skipped: a rule\n  phrased \"present and not X\" is one an attacker satisfies by deleting the\n  field. That covers `Status` and `Destination` (signed-Response only),\n  `Assertion/@ID`, `Assertion/Issuer`, `Conditions`, `Conditions/@NotOnOrAfter`,\n  the `AudienceRestriction`, and, in the bearer confirmation, `Recipient`,\n  `NotOnOrAfter` and — when a request ID is expected — `InResponseTo`. Of the\n  fields the validators read, only these may be missing, each for a reason:\n  - `Conditions/@NotBefore` and `SubjectConfirmationData/@NotBefore` — a\n    missing `NotBefore` only means \"valid from issue\"; when present it is\n    checked;\n  - `Response/Issuer` — optional in SAML Core, and the assertion's own `Issuer`\n    is checked inside the signature; when present it must agree (5b);\n  - `NameID` — surfaced on the result, not trusted for anything.\n- **The signature must cover the element that is read.** A wrapping attack\n  supplies a document holding a genuinely signed fragment beside a forged one;\n  the validator resolves which element each signature covers and reads the\n  assertion's fields from that element only. And since a payload travels on\n  whole — `Saml2PureProvider` hands it to `cookieProvider` — **every**\n  SAML 2.0 `Assertion` or `EncryptedAssertion`, and every SAML 1.x\n  `Assertion` (`urn:oasis:names:tc:SAML:1.0:assertion`), anywhere in the\n  document must be the signed assertion or inside it, under both validators,\n  but never inside a `ds:Signature`, whose subtree an enveloped signature\n  leaves unsigned. An extra assertion in `Extensions`, a sibling or a wrapper\n  ends the login rather than being ignored. Encrypted assertions are not\n  supported.\n- **Several signatures are accepted** when every one verifies against\n  `idpCertificates`, carries exactly one same-document reference, and sits\n  directly inside the element it references. A signature that fails refuses the\n  whole document, even when another covers the element read. A document with no\n  signature is refused.\n- **Unique IDs (1b)** are the wrapping defence again: XML-DSig resolves its\n  reference by `ID`, so a duplicate makes \"which element is signed\" ambiguous.\n  They are refused wherever they appear, before any reference is resolved.\n- **Check 10 is one element, not four fields — and one is enough.** The\n  assertion must carry exactly one `Subject`, holding at least one\n  `SubjectConfirmation`. It is accepted when **at least one** confirmation\n  passes every sub-rule on its own; values scattered across several\n  confirmations do not add up to one. A candidate's sub-rules, in the order\n  they are evaluated: `Method` is `urn:oasis:names:tc:SAML:2.0:cm:bearer`; it\n  holds exactly one `SubjectConfirmationData`; `InResponseTo` equals the\n  expected request ID — or is **absent** for a login declared `idpInitiated`;\n  `Recipient` equals the ACS the response arrived at; `NotOnOrAfter` is\n  present and a valid `xsd:dateTime`; `NotBefore`, if present, is a valid\n  `xsd:dateTime`; `NotOnOrAfter` has not passed beyond `clockSkewMs`;\n  `NotBefore` has arrived within it. When none qualifies, the refusal names\n  every candidate in document order with the first sub-rule it failed —\n  `no bearer confirmation qualifies: #1 Recipient is not the ACS | #2\n  NotOnOrAfter has passed` — listing at most five, then `and N more`.\n- **Check 9 is AND across restrictions, OR within one**, as SAML Core §2.5.1.4\n  says: every `AudienceRestriction` must name you; the `Audience` elements\n  inside one are alternatives.\n- **Dates are parsed strictly.** An `xsd:dateTime` must have real calendar\n  components — `2026-02-30T00:00:00Z`, which `Date.parse` quietly turns into\n  2 March, is refused.\n- **No DTD.** A `<!DOCTYPE` anywhere in the payload is refused at `document`\n  before it is parsed: a SAML message has no use for one, and the document is\n  parsed twice — by `@xmldom/xmldom` 0.9 here and by the 0.8 inside\n  `xml-crypto` — where a DTD is exactly what parsers disagree about.\n- **Any XML fault is a refusal, and nothing reaches the console.** The parser\n  is given an error handler that throws on every level, so a payload it would\n  have repaired — an undeclared entity, say — is refused at `document` rather\n  than validated in its repaired form, and a malformed callback never writes\n  to stderr past your `ILogger`. The same holds for the bearer conversion.\n- **SHA-1 is accepted.** RSA-SHA1 signatures and SHA-1 digests verify, as they\n  do under `xml-crypto`'s defaults, because identity providers still emit them\n  and refusing them would refuse genuine logins. To refuse them, supply an\n  `assertionValidator` of your own that rejects a `SignatureMethod` or\n  `DigestMethod` naming `…xmldsig#rsa-sha1` or `…xmldsig#sha1` before\n  delegating to a shipped validator — and keep `idpEntityId` configured, since\n  the shipped validator inside still refuses without an expected issuer.\n\n#### Refusal messages\n\nSince 4.1.0 no two rules under one `check` share a message, and an element\nthat must appear exactly once says which way it failed — absent, or more than\none. Every value a message takes from the document is JSON-quoted and cut to\n64 characters, so a newline smuggled in as `&#10;` shows as `\\n` and cannot\nforge a log line. Match on `check` in code; the message is for the person\nreading the log. `<n>` is a count of two or more; `\"…\"` is a quoted document\nvalue.\n\n| `check` | message |\n|---|---|\n| `document` | `the SAMLResponse carries a DOCTYPE declaration, which is never accepted` |\n| `document` | `the SAMLResponse did not parse as XML` |\n| `document` | `expected a samlp:Response or a saml:Assertion, got \"…\"` |\n| `document` | `expected the document element to be a samlp:Response, got \"…\"` |\n| `duplicateId` | `the document uses the ID \"…\" more than once, so which element is signed is ambiguous` |\n| `signature` | `the document carries no signature` |\n| `signature` | `the signature element is malformed: \"…\"` |\n| `signature` | `the signature does not verify against any configured certificate` |\n| `signature` | `the signature carries no ds:Reference` |\n| `signature` | `the signature carries <n> ds:Reference; exactly one is allowed` |\n| `signature` | `the signature reference is not a same-document URI: \"…\"` |\n| `signature` | `the signature references \"…\", which is not in the document` |\n| `signature` | `the signature is not inside the element it references, so it does not envelope it` |\n| `signedNode` | `the response carries no direct-child saml:Assertion` |\n| `signedNode` | `the response carries <n> direct-child saml:Assertion; exactly one is allowed` |\n| `signedNode` | `the signature does not cover the samlp:Response this validator requires` |\n| `signedNode` | `the signature does not cover the saml:Assertion this validator requires` |\n| `signedNode` | `the document carries an Assertion or EncryptedAssertion, SAML 2.0 or 1.x, outside the one the signature covers` |\n| `signedNode` | `the document carries an Assertion or EncryptedAssertion inside a ds:Signature, which is never accepted` |\n| `status` | `the response carries no samlp:Status` |\n| `status` | `the response carries <n> samlp:Status; exactly one is allowed` |\n| `status` | `the samlp:Status carries no samlp:StatusCode` |\n| `status` | `the samlp:Status carries <n> samlp:StatusCode; exactly one is allowed` |\n| `status` | `the samlp:StatusCode carries no Value` |\n| `status` | `the identity provider declined the login: \"…\"` |\n| `assertionId` | `the assertion carries no ID` |\n| `issuer` | `the assertion carries no saml:Issuer` |\n| `issuer` | `the assertion carries <n> saml:Issuer; exactly one is allowed` |\n| `issuer` | `the assertion's saml:Issuer is empty` |\n| `issuer` | `no expectedIssuer was configured, so the assertion issuer cannot be trusted` |\n| `issuer` | `the assertion was issued by \"…\", not the trusted issuer` |\n| `issuer` | `the response must carry at most one saml:Issuer` |\n| `issuer` | `the response and the assertion name different issuers` |\n| `conditions` | `the assertion carries no saml:Conditions` |\n| `conditions` | `the assertion carries <n> saml:Conditions; exactly one is allowed` |\n| `notBefore` | `Conditions NotBefore is not a valid xsd:dateTime: \"…\"` |\n| `notBefore` | `the assertion is not valid yet` |\n| `notOnOrAfter` | `Conditions carries no NotOnOrAfter, so the assertion states no lifetime` |\n| `notOnOrAfter` | `Conditions NotOnOrAfter is not a valid xsd:dateTime: \"…\"` |\n| `notOnOrAfter` | `the assertion has expired` |\n| `audience` | `the assertion restricts no audience` |\n| `audience` | `an AudienceRestriction names no audience` |\n| `audience` | `an AudienceRestriction on this assertion does not name us` |\n| `bearerConfirmation` | `the assertion carries no saml:Subject` |\n| `bearerConfirmation` | `the assertion carries <n> saml:Subject; exactly one is allowed` |\n| `bearerConfirmation` | `the saml:Subject holds no SubjectConfirmation` |\n| `bearerConfirmation` | `no bearer confirmation qualifies: #1 <reason> \\| #2 <reason> \\| …` |\n| `destination` | `the response carries no Destination` |\n| `destination` | `the response is addressed to \"…\", not to us` |\n| `replay` | `this assertion has been presented before` |\n\nA `bearerConfirmation` refusal naming candidates lists each one's first failed\nsub-rule, in document order, joined by ` | ` — not `; `, which a count reason\nsuch as `carries 2 SubjectConfirmationData; exactly one is allowed` contains\nitself; past five candidates it ends ` | and N more`, N being how many were\nnot listed. The eleven reasons:\n\n| # | `<reason>`, in the order a candidate is tested |\n|---|---|\n| 1 | `Method is not bearer` |\n| 2 | `carries no SubjectConfirmationData` |\n| 3 | `carries <n> SubjectConfirmationData; exactly one is allowed` |\n| 4 | `InResponseTo is present, but this login sent no request` |\n| 5 | `InResponseTo does not answer our request` |\n| 6 | `Recipient is not the ACS` |\n| 7 | `SubjectConfirmationData has no NotOnOrAfter` |\n| 8 | `SubjectConfirmationData NotOnOrAfter is not a valid xsd:dateTime` |\n| 9 | `SubjectConfirmationData NotBefore is not a valid xsd:dateTime` |\n| 10 | `NotOnOrAfter has passed` |\n| 11 | `NotBefore has not arrived` |\n\nTwo messages from outside a validator changed in 4.1.0 and carry no `check`.\nA provider configured with both `idpInitiated: true` and `authnRequestId`\nthrows a `ValidationError` (`missingFields: ['idpInitiated']`) at\nconstruction: `SAML idpInitiated is true and authnRequestId is set: an\nIdP-initiated login sends no request, so the two describe different logins.\nRemove one of them.` And `Saml2BearerProvider`'s conversion of a validated\npayload into the bearer grant's Assertion throws a plain `Error` whose parser\ntext is quoted the same way — reachable only when a custom validator accepted\na payload that does not parse: `SAML bearer payload is not well-formed XML:\n\"…\"`.\n\n**Expiry comes from the verified document.** A validated assertion's\n`expiresAt` is the earlier of `Conditions/@NotOnOrAfter` and the `NotOnOrAfter`\nof the bearer confirmation accepted — the earliest, if several qualify — so a\nsession cannot outlive a window the assertion itself closed.\n`Saml2PureProvider` takes its session's `expiresAt` from it.\n`parseSamlNotOnOrAfter`, the regular expression over unverified XML it replaces,\nis gone.\n\n**What remains unproven.** The validators verify signatures with `xml-crypto`.\nThey are tested against signatures `xml-crypto` itself produced (through\n`@mcp-abap-adt/auth-mocks`) and against Keycloak, a real identity provider, on\nthe provider stand. Whether every other identity provider's canonicalisation\nmatches is not proven; a refusal at `signature` from a genuine response is the\nsymptom to report.\n\n#### Where the expected request ID comes from\n\n`InResponseTo` must answer the request that was sent — or, where none was sent\nby explicit choice, be absent. The expected ID is decided before validation,\nfrom one of three sources, and never inferred from the assertion:\n\n| Source | When | `InResponseTo` must be |\n|---|---|---|\n| minted | the strategy called `buildAuthorizationUrl`, and the package built the AuthnRequest — `samlCallbackStrategy`, `manualSamlResponseStrategy`, `externalCodeStrategy`, or the default | equal to the ID the package minted |\n| declared | `authnRequestId` is configured | equal to `authnRequestId` |\n| none, by declaration | `idpInitiated: true`, and no request was sent | **absent** |\n\n`authnRequestId` is **required** whenever the package did not build the request\nand the login is not declared IdP-initiated. Two flows trigger it:\n\n- a pre-built `authorizationUrl` — the package cannot read the ID out of a\n  request it did not build;\n- a strategy that returns a payload without calling `buildAuthorizationUrl` —\n  `staticCodeStrategy`, or your own — after a request you sent some other way.\n\nWithout it, the login fails with a `ValidationError` (`missingFields:\n['authnRequestId']`) after the strategy returns and before the assertion is\nread — as a configuration fault, not a refusal blamed on the assertion. A\nstrategy that merely forgot to call the builder must not silently switch the\nprovider into accepting unsolicited responses.\n\n**`idpInitiated: true`** declares that the identity provider started the login\nand no AuthnRequest exists, so the assertion must carry no `InResponseTo`.\n`Saml2BearerProvider` against UAA or XSUAA needs it: both refuse an assertion\ncarrying `InResponseTo` on the saml2-bearer grant. What it gives up is the\n**login-CSRF defence** of a request ID: with one, a response must answer the\nrequest just sent; without it, whoever can deliver a validly signed response\nof their own to your receiver can log your user in as themselves. That is\nsometimes the right trade — for UAA and XSUAA it is the only one — but it must\nbe a decision visible in your configuration. **It is never inferred**: an\nassertion without `InResponseTo` does not make a login IdP-initiated; only\n`idpInitiated: true` does. The other checks apply unchanged.\n\n`idpInitiated: true` together with a request ID is a configuration error too:\nthe two describe different logins. With a declared `authnRequestId` the\nprovider refuses at construction — a `ValidationError` (`missingFields:\n['idpInitiated']`) — before any browser opens. A strategy that calls\n`buildAuthorizationUrl` with no\n`authorizationUrl` configured is refused inside the builder, before a URL — and\nso a request ID — exists: a `ValidationError` with `missingFields:\n['authorizationUrl']`. Use a strategy that does not call the builder, and leave\n`authnRequestId` unset; or configure the identity provider's IdP-initiated SSO\nURL as `authorizationUrl`, which the builder hands over without minting\nanything.\n\n#### Replay\n\nThe shipped replay store is **process-wide**: one module-level in-memory store,\n`defaultReplayStore`, shared by every validator given it in the process — both\n`inBrowser` recipes use it unless `SamlTrust.replayStore` says otherwise. An assertion accepted once is refused as a replay\n(`check: 'replay'`) for as long as it could still be accepted, however many\nproviders are constructed; a store per provider would let a second provider\naccept what the first had seen. It is keyed by `{issuer, assertionId}`, since an\nID is unique only within the identity provider that minted it. Only an assertion\nthat passed every other check is recorded.\n\nWhat it does **not** protect: anything across processes. A second process, a\nrestart, or a horizontally scaled deployment each start with an empty memory.\nFor those, supply a shared store — `replayStore` on a shipped validator's\noptions, or on the `SamlTrust` given to `inBrowser`. Its `recordIfUnseen` must be\natomic — a single conditional write, never a read followed by a write — because\nthat race is exactly the one a replay exploits:\n\n```typescript\nimport type { IAssertionReplayStore } from '@mcp-abap-adt/interfaces-auth';\n\nconst sharedReplayStore: IAssertionReplayStore = {\n  async recordIfUnseen({ issuer, assertionId }, retainUntil) {\n    // e.g. Redis `SET key 1 NX PXAT <ms>`: true only when newly written.\n    return setIfAbsent(\n      `saml-replay:${issuer.length}:${issuer}:${assertionId}`,\n      retainUntil,\n    );\n  },\n};\n```\n\nThe issuer is length-prefixed, as in the in-memory store, because both parts\nmay contain `:` — without the length, issuer `a:b` with ID `c` and issuer `a`\nwith ID `b:c` would share one key, and one would be refused as the other's\nreplay.\n\n`createInMemoryReplayStore()` returns a store of your own, for isolation — a\ntest, or a component that must not share memory with the rest of the process.\nThe in-memory store prunes lazily when consulted, so it holds no timer and\nneeds no disposal.\n\n#### Clock skew\n\n`clockSkewMs` defaults to **`0`**: this package applies no leniency you did not\nchoose. It must be a finite, non-negative integer; anything else fails at\nconstruction. It widens the `NotBefore` and `NotOnOrAfter` checks of both\n`Conditions` and the bearer confirmation. A replay entry is retained until\nthe earlier of `Conditions/@NotOnOrAfter` and the **latest** `NotOnOrAfter` of\na bearer confirmation that answers the request and names the ACS — one not\nopen yet included — plus `clockSkewMs`: the last instant the assertion could\nstill be accepted. That is not `expiresAt`, which takes the earliest\nconfirmation; with confirmations closing at +120 s and +600 s the session ends\nat +120 s, but the second still admits the assertion at +200 s, so the entry\nmust outlive it. Neither window nor tolerance cuts a hole in replay detection.\n\n#","readmeFilename":"README.md"}