authentication

package module
v1.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: MIT Imports: 2 Imported by: 0

README

Authentication Package

OAuth 2.0 authentication providers for gRPC connections in Chainlink Canton. Supports Authorization Code Flow ( interactive user login) and Client Credentials Flow (machine-to-machine).

Quick Start

Client Credentials

For server-to-server authentication:

import "github.com/smartcontractkit/chainlink-canton/authentication/providers/clientcredentials"

provider, err := clientcredentials.NewDiscoveryProvider(
    ctx,
    "https://auth.example.com",
    "client-id",
    "client-secret",
)
Authorization Code (Interactive Login)

For user login flows:

import "github.com/smartcontractkit/chainlink-canton/authentication/providers/authorizationcode"

provider, err := authorizationcode.NewDiscoveryProvider(
    ctx,
    "https://auth.example.com",
    "client-id",
)

Authorization Code Flow

For interactive user authentication via browser login. Requires OAuth server to support PKCE with S256 challenge method. Automatically handles state validation to prevent CSRF attacks. By default, automatically opens the authorization URL in your browser.

Metadata Discovery

Automatically discovers authorization and token endpoints via RFC 8414:

import "github.com/smartcontractkit/chainlink-canton/authentication/providers/authorizationcode"

provider, err := authorizationcode.NewDiscoveryProvider(
    ctx,
    "https://auth.example.com",
    "client-id",
    authorizationcode.WithScopes("daml_ledger_api", "offline_access"),
    authorizationcode.WithOpenBrowser(false), // Disables automatically opening the login URL in the default browser
)
Direct Configuration

If metadata discovery is unavailable:

provider, err := authorizationcode.NewProvider(
    ctx,
    "https://auth.example.com/oauth/authorize",
    "https://auth.example.com/oauth/token",
    "client-id",
)

Additional options are available via the functional options pattern (see package documentation for WithScopes, WithCallbackURL, WithOpenBrowser, etc).

Token Persistence (Keyring)

CLIs can persist tokens in the operating system's native keyring (macOS Keychain, Windows Credential Manager, or the Secret Service on Linux) so users don't have to log in again for every invocation:

provider, err := authorizationcode.NewDiscoveryProvider(
    ctx,
    "https://auth.example.com",
    "client-id",
    authorizationcode.WithScopes("daml_ledger_api", "offline_access"),
    authorizationcode.WithKeyring(true),
)

When enabled, the provider first checks the keyring for a token from a previous login. If a usable token is found (still valid, or renewable via its refresh token), the interactive login is skipped entirely. Otherwise, the login flow runs and the fetched token is stored in the keyring afterward. Tokens are keyed by token endpoint and client ID, and refreshed tokens are written back automatically. A broken or unavailable keyring only prints a warning and falls back to the interactive login.

Client Credentials Flow

For server-to-server authentication. Ideal for automated systems, CI/CD pipelines, and service-to-service communication.

Metadata Discovery

Automatically discovers token endpoint via RFC 8414:

import "github.com/smartcontractkit/chainlink-canton/authentication/providers/clientcredentials"

provider, err := clientcredentials.NewDiscoveryProvider(
    ctx,
    "https://auth.example.com",
    "client-id",
    "client-secret",
    clientcredentials.WithScopes("daml_ledger_api", "admin"),
)
Direct Configuration

If metadata discovery is unavailable:

provider, err := clientcredentials.NewProvider(
    ctx,
    "https://auth.example.com/oauth/token",
    "client-id",
    "client-secret",
)

Additional options are available via the functional options pattern (see package documentation for WithScopes, WithTransportCredentials, etc).

Static Providers

For cases where you already have an access token and don't need OAuth flows:

import "github.com/smartcontractkit/chainlink-canton/authentication/providers/static"

provider := static.NewStaticProvider("access-token")

The static provider enforces TLS transport security and is suitable for remote environments.

Insecure Static Provider

For testing against LocalNet or other non-production environments only:

import "github.com/smartcontractkit/chainlink-canton/authentication/providers/static"

provider := static.NewInsecureStaticProvider("access-token")

The insecure static provider does not enforce transport security and must not be used in production.

Token Management

Both providers automatically handle token lifecycle management: caching, automatic refresh, and thread-safe operations.

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Provider

type Provider interface {
	// TokenSource returns an oauth2.TokenSource that can be used to retrieve access tokens for authenticating with the participant's API endpoints.
	TokenSource() oauth2.TokenSource
	// TransportCredentials returns gRPC transport credentials to be used when connecting to the participant's RPC endpoints.
	TransportCredentials() credentials.TransportCredentials
	// PerRPCCredentials returns gRPC per-RPC credentials to be used when connecting to the participant's gRPC endpoints.
	PerRPCCredentials() credentials.PerRPCCredentials
}

Provider provides authentication credentials for connecting to a Canton participant's API endpoints. The Provider acts as both a raw token-source for HTTP API authentication, and a gRPC credentials provider for gRPC endpoint authentication.

Implementations of this interface can implement different means of fetching and refreshing authentication tokens, as well as enforcing different levels of transport security. The specific implementation of the Provider should be chosen based on the environment being connected to (e.g. LocalNet vs. production, i.e. CI/OIDC).

Directories

Path Synopsis
authorizationcode
Package authorizationcode provides OAuth2 authorization code flow authentication for gRPC connections.
Package authorizationcode provides OAuth2 authorization code flow authentication for gRPC connections.
clientcredentials
Package clientcredentials provides OAuth2 client credentials flow authentication for gRPC connections.
Package clientcredentials provides OAuth2 client credentials flow authentication for gRPC connections.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL