Skip to content

Repository files navigation

Signet SDK for Go

Lint and Testing CodeQL Trivy Security Scan codecov Go Reference GitHub release

Go SDK for Signet. Requires Go 1.26+.

Installation

go get github.com/go-signet/sdk-go

Packages

Package Description
credstore Secure credential storage with OS keyring integration and file-based fallback
oauth OAuth 2.0 token client (resource indicators, OBO, Device/Auth Code, Client Credentials, Refresh, Introspect)
discovery OIDC auto-discovery from /.well-known/openid-configuration with caching
authflow CLI flow orchestration (Device Code polling, Auth Code + PKCE, auto-refresh TokenSource with persistent storage)
middleware net/http Bearer token validation middleware (online: tokeninfo / introspection per request)
jwksauth net/http Bearer token validation middleware (offline: cached JWKS, single + multi-issuer)
bearerauth Framework-neutral verifier for routes accepting either a JWT (offline) or a sgk_… Personal API Key (online)
clientcreds Thread-safe Client Credentials token source with auto-cache, HTTPClient() and RoundTripper() for M2M

Package dependency graph

credstore (storage)     discovery (OIDC endpoint URLs)
    |    \                  |
    |     \                 v
    |      +----> oauth <---+
    |             / | \  \
    |            /  |  \  \
    v           v   v   v  v
    +---> authflow  middleware  clientcreds  bearerauth
                                                  ^
jwksauth — standalone (wraps coreos/go-oidc)      |
    |                                             |
    +---------------------------------------------+
      (bearerauth injects a jwksauth.TokenVerifier,
       reuses oauth.Client for sgk_ keys, and uses
       discovery in its one-call New constructor)

Online vs. offline token validation

middleware, jwksauth, and bearerauth all validate an incoming Authorization: Bearer … credential, with different trade-offs:

Concern jwksauth (offline JWKS) middleware (online endpoint) bearerauth (mixed)
Per-request round-trips None (signature math only) One per request (tokeninfo/introspect) None for JWTs, one per sgk_… key
Verification latency Microseconds 10–50 ms + auth-server tail Microseconds / 10–50 ms by credential
Revocation visibility After exp of the access token Instant After exp (JWT) / instant (key)
Survives auth-server outage Yes (after first JWKS fetch) No JWT routes yes, key routes no
Opaque (non-JWT) tokens Not supported Supported Signet Personal API Keys (sgk_…)
Multi-issuer support Built-in (MultiVerifier) One client per issuer No — Policy pins exactly one issuer
HTTP integration net/http middleware net/http middleware None — Verify(ctx, raw) only

Reach for bearerauth when one route must accept both credential kinds, or when you need a verifier that plugs into a non-net/http router (gin, echo, fiber, connect) without the SDK writing responses for you.

Resource indicators and OBO

All token grants accept RFC 8707 resource indicators. Interactive flows and the root signet.New facade use WithResources; the client-credentials token source has its own option of the same name. API A performs Signet's single-hop OBO exchange through oauth.Client.ExchangeOnBehalfOf.

API B should validate delegated JWTs locally with jwksauth or bearerauth so it can enforce the signed audience, user subject, scopes, and act actor. Under Signet's default ownership gate, introspection by API B returns an active-only verdict; use that verdict only as an optional live revocation/lineage check, not as identity metadata.

Migrating to resource-aware APIs

This update intentionally breaks source compatibility. Add the final resources []string argument to OAuth grant calls (nil omits resources), and replace authflow.DeviceFlowOption / authflow.AuthCodeFlowOption with authflow.FlowOption. Match WithTokenResources to interactive-flow resources.

New fields also change the positional shapes of oauth.TokenInfo, oauth.IntrospectionResult, jwksauth.Claims, and bearerauth.Identity. Replace unkeyed composite literals with keyed literals, such as oauth.TokenInfo{Active: true} and oauth.IntrospectionResult{Active: true}; existing keyed literals may omit the new fields.

Development

# Run tests
make test

# Run linter
make lint

# Format code
make fmt

License

See the LICENSE file for details.

About

Signet SDK for Go — OAuth 2.0 device/PKCE flows, JWKS-based JWT verification, and secure credential storage with OS keyring integration

Topics

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages