Forge documentation
Library referenceSwift

ForgeAuth

Swift ForgeAuth library product.

Swift ForgeAuth library product.

Package contract

FieldValue
Languageswift
Source versionSwift package source snapshot
Manifestforge-swift/Package.swift
Source files4
EvidenceSource reference; registry publication and runtime conformance are separate checks

Import boundary

import ForgeAuth

Use a source checkout or your verified private registry. Manifest coordinates identify the package; they do not establish that a public registry release exists.

Source reference

Download package reference JSON. Each original source file and generated declaration artifact has its own SHA-256 digest. Function bodies and constant values are omitted from downloads. These are source declaration inventories, not compiler-resolved rustdoc, TypeDoc, DocC, or Dokka output. Private modules can contain public declarations that are not reachable through the package boundary; consult the entry point before importing.

AuthError.swift

Read declaration text · 8 declaration entries

public enum ForgeAuthError: Error, Sendable, Equatable

public var errorDescription: String?

public var isExpired: Bool

public var isInsufficientScope: Bool

public var isCapabilityEscalation: Bool

public var isDelegationDenied: Bool

public var isInvalidToken: Bool

public var errorCode: String

Capability.swift

Read declaration text · 33 declaration entries

public struct ToolPattern: Codable, Sendable, Equatable, Hashable

public let pattern: String

/// Creates a new tool pattern.
///
/// - Parameter pattern: The pattern string. Use `*` for wildcard matching.
public init(_ pattern: String)

public init(_ pattern: String)

public func matches(_ toolName: String) -> Bool

public init(from decoder: Decoder) throws

public func encode(to encoder: Encoder) throws

public struct Capability: Codable, Sendable, Equatable

public let toolPattern: ToolPattern

/// An optional human-readable label for this capability.
public let label: String?

/// Optional scope string in `service:resource:action` format.
///
/// When present, this is the canonical scope string used for ACT scope
/// matching. When absent, the scope is derived from the tool pattern
/// as `forge:tool.<pattern>:execute`.
public let scope: String?

/// Creates a new capability.
///
/// - Parameters:
///   - toolPattern: The tool name pattern.
///   - label: An optional human-readable label.
///   - scope: An optional scope string in `service:resource:action` format.
public init(toolPattern: ToolPattern, label: String?;

public let label: String?

/// Optional scope string in `service:resource:action` format.
///
/// When present, this is the canonical scope string used for ACT scope
/// matching. When absent, the scope is derived from the tool pattern
/// as `forge:tool.<pattern>:execute`.
public let scope: String?

/// Creates a new capability.
///
/// - Parameters:
///   - toolPattern: The tool name pattern.
///   - label: An optional human-readable label.
///   - scope: An optional scope string in `service:resource:action` format.
public init(toolPattern: ToolPattern, label: String?;

public let scope: String?

/// Creates a new capability.
///
/// - Parameters:
///   - toolPattern: The tool name pattern.
///   - label: An optional human-readable label.
///   - scope: An optional scope string in `service:resource:action` format.
public init(toolPattern: ToolPattern, label: String?;

public init(toolPattern: ToolPattern, label: String?;

public static func tool(_ toolName: String) -> Capability

public static func wildcard() -> Capability

public struct ArsenalACT: Codable, Sendable, Equatable

public let id: String

/// The OAS DID of the agent this token is issued to.
public let agentDid: String

/// The issuer identifier.
public let issuer: String

/// The audience identifier.
public let audience: String

/// The capabilities granted by this token.
public let capabilities: [Capability]

/// The scope strings granted by this token (in `service:resource:action` format).
///
/// These are the canonical scopes used for scope matching. If a capability has
/// an explicit scope, it is included here. Otherwise, the scope is derived from
/// the tool pattern.
public let scopes: [String]

/// When the token was issued.
public let issuedAt: Timestamp

/// When the token becomes valid (not-before).
public let notBefore: Timestamp

public let agentDid: String

/// The issuer identifier.
public let issuer: String

/// The audience identifier.
public let audience: String

/// The capabilities granted by this token.
public let capabilities: [Capability]

/// The scope strings granted by this token (in `service:resource:action` format).
///
/// These are the canonical scopes used for scope matching. If a capability has
/// an explicit scope, it is included here. Otherwise, the scope is derived from
/// the tool pattern.
public let scopes: [String]

/// When the token was issued.
public let issuedAt: Timestamp

/// When the token becomes valid (not-before).
public let notBefore: Timestamp

/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?

public let issuer: String

/// The audience identifier.
public let audience: String

/// The capabilities granted by this token.
public let capabilities: [Capability]

/// The scope strings granted by this token (in `service:resource:action` format).
///
/// These are the canonical scopes used for scope matching. If a capability has
/// an explicit scope, it is included here. Otherwise, the scope is derived from
/// the tool pattern.
public let scopes: [String]

/// When the token was issued.
public let issuedAt: Timestamp

/// When the token becomes valid (not-before).
public let notBefore: Timestamp

/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?

/// The parent token ID if this token was delegated.
public let parentTokenId: String?

public let audience: String

/// The capabilities granted by this token.
public let capabilities: [Capability]

/// The scope strings granted by this token (in `service:resource:action` format).
///
/// These are the canonical scopes used for scope matching. If a capability has
/// an explicit scope, it is included here. Otherwise, the scope is derived from
/// the tool pattern.
public let scopes: [String]

/// When the token was issued.
public let issuedAt: Timestamp

/// When the token becomes valid (not-before).
public let notBefore: Timestamp

/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?

/// The parent token ID if this token was delegated.
public let parentTokenId: String?

/// Whether delegation is allowed from this token.
public let allowDelegation: Bool

public let capabilities: [Capability]

/// The scope strings granted by this token (in `service:resource:action` format).
///
/// These are the canonical scopes used for scope matching. If a capability has
/// an explicit scope, it is included here. Otherwise, the scope is derived from
/// the tool pattern.
public let scopes: [String]

/// When the token was issued.
public let issuedAt: Timestamp

/// When the token becomes valid (not-before).
public let notBefore: Timestamp

/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?

/// The parent token ID if this token was delegated.
public let parentTokenId: String?

/// Whether delegation is allowed from this token.
public let allowDelegation: Bool

/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32

public let scopes: [String]

/// When the token was issued.
public let issuedAt: Timestamp

/// When the token becomes valid (not-before).
public let notBefore: Timestamp

/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?

/// The parent token ID if this token was delegated.
public let parentTokenId: String?

/// Whether delegation is allowed from this token.
public let allowDelegation: Bool

/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32

/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64

/// Creates a new Arsenal ACT.
///
/// - Parameters:

public let issuedAt: Timestamp

/// When the token becomes valid (not-before).
public let notBefore: Timestamp

/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?

/// The parent token ID if this token was delegated.
public let parentTokenId: String?

/// Whether delegation is allowed from this token.
public let allowDelegation: Bool

/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32

/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64

/// Creates a new Arsenal ACT.
///
/// - Parameters:
///   - id: Unique token identifier.
///   - agentDid: The agent's OAS DID.
///   - issuer: The issuer identifier.

public let notBefore: Timestamp

/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?

/// The parent token ID if this token was delegated.
public let parentTokenId: String?

/// Whether delegation is allowed from this token.
public let allowDelegation: Bool

/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32

/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64

/// Creates a new Arsenal ACT.
///
/// - Parameters:
///   - id: Unique token identifier.
///   - agentDid: The agent's OAS DID.
///   - issuer: The issuer identifier.
///   - audience: The audience identifier.
///   - capabilities: The capabilities granted.
///   - scopes: The scope strings granted.

public let expiresAt: Timestamp?

/// The parent token ID if this token was delegated.
public let parentTokenId: String?

/// Whether delegation is allowed from this token.
public let allowDelegation: Bool

/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32

/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64

/// Creates a new Arsenal ACT.
///
/// - Parameters:
///   - id: Unique token identifier.
///   - agentDid: The agent's OAS DID.
///   - issuer: The issuer identifier.
///   - audience: The audience identifier.
///   - capabilities: The capabilities granted.
///   - scopes: The scope strings granted.
///   - issuedAt: When the token was issued.
///   - notBefore: When the token becomes valid.
///   - expiresAt: When the token expires, or nil.

public let parentTokenId: String?

/// Whether delegation is allowed from this token.
public let allowDelegation: Bool

/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32

/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64

/// Creates a new Arsenal ACT.
///
/// - Parameters:
///   - id: Unique token identifier.
///   - agentDid: The agent's OAS DID.
///   - issuer: The issuer identifier.
///   - audience: The audience identifier.
///   - capabilities: The capabilities granted.
///   - scopes: The scope strings granted.
///   - issuedAt: When the token was issued.
///   - notBefore: When the token becomes valid.
///   - expiresAt: When the token expires, or nil.
///   - parentTokenId: The parent token ID for delegated tokens.
///   - allowDelegation: Whether delegation is allowed.
///   - maxDelegationDepth: Maximum delegation depth.

public let allowDelegation: Bool

/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32

/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64

/// Creates a new Arsenal ACT.
///
/// - Parameters:
///   - id: Unique token identifier.
///   - agentDid: The agent's OAS DID.
///   - issuer: The issuer identifier.
///   - audience: The audience identifier.
///   - capabilities: The capabilities granted.
///   - scopes: The scope strings granted.
///   - issuedAt: When the token was issued.
///   - notBefore: When the token becomes valid.
///   - expiresAt: When the token expires, or nil.
///   - parentTokenId: The parent token ID for delegated tokens.
///   - allowDelegation: Whether delegation is allowed.
///   - maxDelegationDepth: Maximum delegation depth.
///   - minTtlReduction: Minimum TTL reduction for delegation (seconds).
public init(
id: String,

public let maxDelegationDepth: UInt32

/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64

/// Creates a new Arsenal ACT.
///
/// - Parameters:
///   - id: Unique token identifier.
///   - agentDid: The agent's OAS DID.
///   - issuer: The issuer identifier.
///   - audience: The audience identifier.
///   - capabilities: The capabilities granted.
///   - scopes: The scope strings granted.
///   - issuedAt: When the token was issued.
///   - notBefore: When the token becomes valid.
///   - expiresAt: When the token expires, or nil.
///   - parentTokenId: The parent token ID for delegated tokens.
///   - allowDelegation: Whether delegation is allowed.
///   - maxDelegationDepth: Maximum delegation depth.
///   - minTtlReduction: Minimum TTL reduction for delegation (seconds).
public init(
id: String,
agentDid: String,
issuer: String,
audience: String,

public let minTtlReduction: Int64

/// Creates a new Arsenal ACT.
///
/// - Parameters:
///   - id: Unique token identifier.
///   - agentDid: The agent's OAS DID.
///   - issuer: The issuer identifier.
///   - audience: The audience identifier.
///   - capabilities: The capabilities granted.
///   - scopes: The scope strings granted.
///   - issuedAt: When the token was issued.
///   - notBefore: When the token becomes valid.
///   - expiresAt: When the token expires, or nil.
///   - parentTokenId: The parent token ID for delegated tokens.
///   - allowDelegation: Whether delegation is allowed.
///   - maxDelegationDepth: Maximum delegation depth.
///   - minTtlReduction: Minimum TTL reduction for delegation (seconds).
public init(
id: String,
agentDid: String,
issuer: String,
audience: String,
capabilities: [Capability],
scopes: [String],
issuedAt: Timestamp;

public init(
id: String,
agentDid: String,
issuer: String,
audience: String,
capabilities: [Capability],
scopes: [String],
issuedAt: Timestamp;

public var isExpired: Bool

public var remainingTtlSeconds: Int64?

public func verifyACT(_ act: ArsenalACT) throws

public func extractScopes(_ act: ArsenalACT) -> [String]

public func actAllowsScope(_ act: ArsenalACT, scope: String) throws -> Bool

Delegation.swift

Read declaration text · 11 declaration entries

public struct DelegationRequest: Sendable

public let parentACT: ArsenalACT
/// The parent agent's OAS DID.
public let parentDid: String
/// The child agent's OAS DID.
public let childDid: String
/// The capabilities requested for the child agent.
///
/// Must be a subset of the parent's capabilities.
public let requestedCapabilities: [Capability]
/// The scope strings requested for the child agent.
///
/// Must be a subset of the parent's scopes.
public let requestedScopes: [String]

/// Creates a new delegation request.
///
/// - Parameters:
///   - parentACT: The parent agent's Arsenal ACT.
///   - parentDid: The parent agent's OAS DID.
///   - childDid: The child agent's OAS DID.
///   - requestedCapabilities: The capabilities requested for the child.
///   - requestedScopes: The scope strings requested for the child.
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,

public let parentDid: String
/// The child agent's OAS DID.
public let childDid: String
/// The capabilities requested for the child agent.
///
/// Must be a subset of the parent's capabilities.
public let requestedCapabilities: [Capability]
/// The scope strings requested for the child agent.
///
/// Must be a subset of the parent's scopes.
public let requestedScopes: [String]

/// Creates a new delegation request.
///
/// - Parameters:
///   - parentACT: The parent agent's Arsenal ACT.
///   - parentDid: The parent agent's OAS DID.
///   - childDid: The child agent's OAS DID.
///   - requestedCapabilities: The capabilities requested for the child.
///   - requestedScopes: The scope strings requested for the child.
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
requestedCapabilities: [Capability],
requestedScopes: [String]

public let childDid: String
/// The capabilities requested for the child agent.
///
/// Must be a subset of the parent's capabilities.
public let requestedCapabilities: [Capability]
/// The scope strings requested for the child agent.
///
/// Must be a subset of the parent's scopes.
public let requestedScopes: [String]

/// Creates a new delegation request.
///
/// - Parameters:
///   - parentACT: The parent agent's Arsenal ACT.
///   - parentDid: The parent agent's OAS DID.
///   - childDid: The child agent's OAS DID.
///   - requestedCapabilities: The capabilities requested for the child.
///   - requestedScopes: The scope strings requested for the child.
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
requestedCapabilities: [Capability],
requestedScopes: [String]
)

public let requestedCapabilities: [Capability]
/// The scope strings requested for the child agent.
///
/// Must be a subset of the parent's scopes.
public let requestedScopes: [String]

/// Creates a new delegation request.
///
/// - Parameters:
///   - parentACT: The parent agent's Arsenal ACT.
///   - parentDid: The parent agent's OAS DID.
///   - childDid: The child agent's OAS DID.
///   - requestedCapabilities: The capabilities requested for the child.
///   - requestedScopes: The scope strings requested for the child.
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
requestedCapabilities: [Capability],
requestedScopes: [String]
)

public let requestedScopes: [String]

/// Creates a new delegation request.
///
/// - Parameters:
///   - parentACT: The parent agent's Arsenal ACT.
///   - parentDid: The parent agent's OAS DID.
///   - childDid: The child agent's OAS DID.
///   - requestedCapabilities: The capabilities requested for the child.
///   - requestedScopes: The scope strings requested for the child.
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
requestedCapabilities: [Capability],
requestedScopes: [String]
)

public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
requestedCapabilities: [Capability],
requestedScopes: [String]
)

public struct DelegationManager: Sendable

public init()

public func delegateCapabilities(_ request: DelegationRequest) throws -> ArsenalACT

public func delegateCapabilities(_ request: DelegationRequest) throws -> ArsenalACT

ToolAuth.swift

Read declaration text · 14 declaration entries

public struct ToolAuthorizationRequest: Sendable

public let agentDid: AgentDid
/// The tool being invoked.
public let toolName: String
/// The tool tier.
public let toolTier: ToolTier
/// The ACT to check against, or `nil` for legacy mode.
public let act: ArsenalACT?

/// Creates a new tool authorization request.
///
/// - Parameters:
///   - agentDid: The agent's OAS DID.
///   - toolName: The tool being invoked.
///   - toolTier: The tool tier classification.
///   - act: The Arsenal ACT to check, or `nil` for legacy mode.
public init(agentDid: AgentDid, toolName: String, toolTier: ToolTier, act: ArsenalACT?)

public let toolName: String
/// The tool tier.
public let toolTier: ToolTier
/// The ACT to check against, or `nil` for legacy mode.
public let act: ArsenalACT?

/// Creates a new tool authorization request.
///
/// - Parameters:
///   - agentDid: The agent's OAS DID.
///   - toolName: The tool being invoked.
///   - toolTier: The tool tier classification.
///   - act: The Arsenal ACT to check, or `nil` for legacy mode.
public init(agentDid: AgentDid, toolName: String, toolTier: ToolTier, act: ArsenalACT?)

public let toolTier: ToolTier
/// The ACT to check against, or `nil` for legacy mode.
public let act: ArsenalACT?

/// Creates a new tool authorization request.
///
/// - Parameters:
///   - agentDid: The agent's OAS DID.
///   - toolName: The tool being invoked.
///   - toolTier: The tool tier classification.
///   - act: The Arsenal ACT to check, or `nil` for legacy mode.
public init(agentDid: AgentDid, toolName: String, toolTier: ToolTier, act: ArsenalACT?)

public let act: ArsenalACT?

/// Creates a new tool authorization request.
///
/// - Parameters:
///   - agentDid: The agent's OAS DID.
///   - toolName: The tool being invoked.
///   - toolTier: The tool tier classification.
///   - act: The Arsenal ACT to check, or `nil` for legacy mode.
public init(agentDid: AgentDid, toolName: String, toolTier: ToolTier, act: ArsenalACT?)

public init(agentDid: AgentDid, toolName: String, toolTier: ToolTier, act: ArsenalACT?)

public enum ToolAuthorizationDecision: Sendable, Equatable

public var isAllowed: Bool

public var isDenied: Bool

public var isLegacyMode: Bool

public struct ToolAuthorizer: Sendable

public init()

public func authorize(_ request: ToolAuthorizationRequest) throws -> ToolAuthorizationDecision

public func authorizeToolInvocation(_ request: ToolAuthorizationRequest) throws -> ToolAuthorizationDecision

Continue

On this page