Go SDK for Signet. Requires Go 1.26+.
go get github.com/go-signet/sdk-go| Package | Description |
|---|---|
| credstore | Secure credential storage with OS keyring integration and file-based fallback |
| oauth | OAuth 2.0 token client (resource indicators, OBO, Device/Auth Code, Client Credentials, Refresh, Introspect) |
| discovery | OIDC auto-discovery from /.well-known/openid-configuration with caching |
| authflow | CLI flow orchestration (Device Code polling, Auth Code + PKCE, auto-refresh TokenSource with persistent storage) |
| middleware | net/http Bearer token validation middleware (online: tokeninfo / introspection per request) |
| jwksauth | net/http Bearer token validation middleware (offline: cached JWKS, single + multi-issuer) |
| bearerauth | Framework-neutral verifier for routes accepting either a JWT (offline) or a sgk_… Personal API Key (online) |
| clientcreds | Thread-safe Client Credentials token source with auto-cache, HTTPClient() and RoundTripper() for M2M |
credstore (storage) discovery (OIDC endpoint URLs)
| \ |
| \ v
| +----> oauth <---+
| / | \ \
| / | \ \
v v v v v
+---> authflow middleware clientcreds bearerauth
^
jwksauth — standalone (wraps coreos/go-oidc) |
| |
+---------------------------------------------+
(bearerauth injects a jwksauth.TokenVerifier,
reuses oauth.Client for sgk_ keys, and uses
discovery in its one-call New constructor)middleware, jwksauth, and bearerauth all validate an incoming
Authorization: Bearer … credential, with different trade-offs:
| Concern | jwksauth (offline JWKS) |
middleware (online endpoint) |
bearerauth (mixed) |
|---|---|---|---|
| Per-request round-trips | None (signature math only) | One per request (tokeninfo/introspect) | None for JWTs, one per sgk_… key |
| Verification latency | Microseconds | 10–50 ms + auth-server tail | Microseconds / 10–50 ms by credential |
| Revocation visibility | After exp of the access token |
Instant | After exp (JWT) / instant (key) |
| Survives auth-server outage | Yes (after first JWKS fetch) | No | JWT routes yes, key routes no |
| Opaque (non-JWT) tokens | Not supported | Supported | Signet Personal API Keys (sgk_…) |
| Multi-issuer support | Built-in (MultiVerifier) |
One client per issuer | No — Policy pins exactly one issuer |
| HTTP integration | net/http middleware |
net/http middleware |
None — Verify(ctx, raw) only |
Reach for bearerauth when one route must accept both credential kinds, or
when you need a verifier that plugs into a non-net/http router (gin, echo,
fiber, connect) without the SDK writing responses for you.
All token grants accept RFC 8707 resource indicators. Interactive flows and the
root signet.New facade use WithResources; the client-credentials token
source has its own option of the same name. API A performs Signet's single-hop
OBO exchange through oauth.Client.ExchangeOnBehalfOf.
API B should validate delegated JWTs locally with jwksauth or bearerauth so
it can enforce the signed audience, user subject, scopes, and act actor. Under
Signet's default ownership gate, introspection by API B returns an active-only
verdict; use that verdict only as an optional live revocation/lineage check,
not as identity metadata.
This update intentionally breaks source compatibility. Add the final
resources []string argument to OAuth grant calls (nil omits resources), and
replace authflow.DeviceFlowOption / authflow.AuthCodeFlowOption with
authflow.FlowOption. Match WithTokenResources to interactive-flow resources.
New fields also change the positional shapes of oauth.TokenInfo,
oauth.IntrospectionResult, jwksauth.Claims, and bearerauth.Identity.
Replace unkeyed composite literals with keyed literals, such as
oauth.TokenInfo{Active: true} and oauth.IntrospectionResult{Active: true};
existing keyed literals may omit the new fields.
# Run tests
make test
# Run linter
make lint
# Format code
make fmtSee the LICENSE file for details.