ForgeAuth
Swift ForgeAuth library product.
Swift ForgeAuth library product.
Package contract
| Field | Value |
|---|---|
| Language | swift |
| Source version | Swift package source snapshot |
| Manifest | forge-swift/Package.swift |
| Source files | 4 |
| Evidence | Source reference; registry publication and runtime conformance are separate checks |
Import boundary
import ForgeAuthUse a source checkout or your verified private registry. Manifest coordinates identify the package; they do not establish that a public registry release exists.
Source reference
Download package reference JSON. Each original source file and generated declaration artifact has its own SHA-256 digest. Function bodies and constant values are omitted from downloads. These are source declaration inventories, not compiler-resolved rustdoc, TypeDoc, DocC, or Dokka output. Private modules can contain public declarations that are not reachable through the package boundary; consult the entry point before importing.
AuthError.swift
Read declaration text · 8 declaration entries
public enum ForgeAuthError: Error, Sendable, Equatable
public var errorDescription: String?
public var isExpired: Bool
public var isInsufficientScope: Bool
public var isCapabilityEscalation: Bool
public var isDelegationDenied: Bool
public var isInvalidToken: Bool
public var errorCode: StringCapability.swift
Read declaration text · 33 declaration entries
public struct ToolPattern: Codable, Sendable, Equatable, Hashable
public let pattern: String
/// Creates a new tool pattern.
///
/// - Parameter pattern: The pattern string. Use `*` for wildcard matching.
public init(_ pattern: String)
public init(_ pattern: String)
public func matches(_ toolName: String) -> Bool
public init(from decoder: Decoder) throws
public func encode(to encoder: Encoder) throws
public struct Capability: Codable, Sendable, Equatable
public let toolPattern: ToolPattern
/// An optional human-readable label for this capability.
public let label: String?
/// Optional scope string in `service:resource:action` format.
///
/// When present, this is the canonical scope string used for ACT scope
/// matching. When absent, the scope is derived from the tool pattern
/// as `forge:tool.<pattern>:execute`.
public let scope: String?
/// Creates a new capability.
///
/// - Parameters:
/// - toolPattern: The tool name pattern.
/// - label: An optional human-readable label.
/// - scope: An optional scope string in `service:resource:action` format.
public init(toolPattern: ToolPattern, label: String?;
public let label: String?
/// Optional scope string in `service:resource:action` format.
///
/// When present, this is the canonical scope string used for ACT scope
/// matching. When absent, the scope is derived from the tool pattern
/// as `forge:tool.<pattern>:execute`.
public let scope: String?
/// Creates a new capability.
///
/// - Parameters:
/// - toolPattern: The tool name pattern.
/// - label: An optional human-readable label.
/// - scope: An optional scope string in `service:resource:action` format.
public init(toolPattern: ToolPattern, label: String?;
public let scope: String?
/// Creates a new capability.
///
/// - Parameters:
/// - toolPattern: The tool name pattern.
/// - label: An optional human-readable label.
/// - scope: An optional scope string in `service:resource:action` format.
public init(toolPattern: ToolPattern, label: String?;
public init(toolPattern: ToolPattern, label: String?;
public static func tool(_ toolName: String) -> Capability
public static func wildcard() -> Capability
public struct ArsenalACT: Codable, Sendable, Equatable
public let id: String
/// The OAS DID of the agent this token is issued to.
public let agentDid: String
/// The issuer identifier.
public let issuer: String
/// The audience identifier.
public let audience: String
/// The capabilities granted by this token.
public let capabilities: [Capability]
/// The scope strings granted by this token (in `service:resource:action` format).
///
/// These are the canonical scopes used for scope matching. If a capability has
/// an explicit scope, it is included here. Otherwise, the scope is derived from
/// the tool pattern.
public let scopes: [String]
/// When the token was issued.
public let issuedAt: Timestamp
/// When the token becomes valid (not-before).
public let notBefore: Timestamp
public let agentDid: String
/// The issuer identifier.
public let issuer: String
/// The audience identifier.
public let audience: String
/// The capabilities granted by this token.
public let capabilities: [Capability]
/// The scope strings granted by this token (in `service:resource:action` format).
///
/// These are the canonical scopes used for scope matching. If a capability has
/// an explicit scope, it is included here. Otherwise, the scope is derived from
/// the tool pattern.
public let scopes: [String]
/// When the token was issued.
public let issuedAt: Timestamp
/// When the token becomes valid (not-before).
public let notBefore: Timestamp
/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?
public let issuer: String
/// The audience identifier.
public let audience: String
/// The capabilities granted by this token.
public let capabilities: [Capability]
/// The scope strings granted by this token (in `service:resource:action` format).
///
/// These are the canonical scopes used for scope matching. If a capability has
/// an explicit scope, it is included here. Otherwise, the scope is derived from
/// the tool pattern.
public let scopes: [String]
/// When the token was issued.
public let issuedAt: Timestamp
/// When the token becomes valid (not-before).
public let notBefore: Timestamp
/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?
/// The parent token ID if this token was delegated.
public let parentTokenId: String?
public let audience: String
/// The capabilities granted by this token.
public let capabilities: [Capability]
/// The scope strings granted by this token (in `service:resource:action` format).
///
/// These are the canonical scopes used for scope matching. If a capability has
/// an explicit scope, it is included here. Otherwise, the scope is derived from
/// the tool pattern.
public let scopes: [String]
/// When the token was issued.
public let issuedAt: Timestamp
/// When the token becomes valid (not-before).
public let notBefore: Timestamp
/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?
/// The parent token ID if this token was delegated.
public let parentTokenId: String?
/// Whether delegation is allowed from this token.
public let allowDelegation: Bool
public let capabilities: [Capability]
/// The scope strings granted by this token (in `service:resource:action` format).
///
/// These are the canonical scopes used for scope matching. If a capability has
/// an explicit scope, it is included here. Otherwise, the scope is derived from
/// the tool pattern.
public let scopes: [String]
/// When the token was issued.
public let issuedAt: Timestamp
/// When the token becomes valid (not-before).
public let notBefore: Timestamp
/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?
/// The parent token ID if this token was delegated.
public let parentTokenId: String?
/// Whether delegation is allowed from this token.
public let allowDelegation: Bool
/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32
public let scopes: [String]
/// When the token was issued.
public let issuedAt: Timestamp
/// When the token becomes valid (not-before).
public let notBefore: Timestamp
/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?
/// The parent token ID if this token was delegated.
public let parentTokenId: String?
/// Whether delegation is allowed from this token.
public let allowDelegation: Bool
/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32
/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64
/// Creates a new Arsenal ACT.
///
/// - Parameters:
public let issuedAt: Timestamp
/// When the token becomes valid (not-before).
public let notBefore: Timestamp
/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?
/// The parent token ID if this token was delegated.
public let parentTokenId: String?
/// Whether delegation is allowed from this token.
public let allowDelegation: Bool
/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32
/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64
/// Creates a new Arsenal ACT.
///
/// - Parameters:
/// - id: Unique token identifier.
/// - agentDid: The agent's OAS DID.
/// - issuer: The issuer identifier.
public let notBefore: Timestamp
/// When the token expires, or `nil` for non-expiring tokens.
public let expiresAt: Timestamp?
/// The parent token ID if this token was delegated.
public let parentTokenId: String?
/// Whether delegation is allowed from this token.
public let allowDelegation: Bool
/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32
/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64
/// Creates a new Arsenal ACT.
///
/// - Parameters:
/// - id: Unique token identifier.
/// - agentDid: The agent's OAS DID.
/// - issuer: The issuer identifier.
/// - audience: The audience identifier.
/// - capabilities: The capabilities granted.
/// - scopes: The scope strings granted.
public let expiresAt: Timestamp?
/// The parent token ID if this token was delegated.
public let parentTokenId: String?
/// Whether delegation is allowed from this token.
public let allowDelegation: Bool
/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32
/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64
/// Creates a new Arsenal ACT.
///
/// - Parameters:
/// - id: Unique token identifier.
/// - agentDid: The agent's OAS DID.
/// - issuer: The issuer identifier.
/// - audience: The audience identifier.
/// - capabilities: The capabilities granted.
/// - scopes: The scope strings granted.
/// - issuedAt: When the token was issued.
/// - notBefore: When the token becomes valid.
/// - expiresAt: When the token expires, or nil.
public let parentTokenId: String?
/// Whether delegation is allowed from this token.
public let allowDelegation: Bool
/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32
/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64
/// Creates a new Arsenal ACT.
///
/// - Parameters:
/// - id: Unique token identifier.
/// - agentDid: The agent's OAS DID.
/// - issuer: The issuer identifier.
/// - audience: The audience identifier.
/// - capabilities: The capabilities granted.
/// - scopes: The scope strings granted.
/// - issuedAt: When the token was issued.
/// - notBefore: When the token becomes valid.
/// - expiresAt: When the token expires, or nil.
/// - parentTokenId: The parent token ID for delegated tokens.
/// - allowDelegation: Whether delegation is allowed.
/// - maxDelegationDepth: Maximum delegation depth.
public let allowDelegation: Bool
/// Maximum delegation depth permitted from this token.
public let maxDelegationDepth: UInt32
/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64
/// Creates a new Arsenal ACT.
///
/// - Parameters:
/// - id: Unique token identifier.
/// - agentDid: The agent's OAS DID.
/// - issuer: The issuer identifier.
/// - audience: The audience identifier.
/// - capabilities: The capabilities granted.
/// - scopes: The scope strings granted.
/// - issuedAt: When the token was issued.
/// - notBefore: When the token becomes valid.
/// - expiresAt: When the token expires, or nil.
/// - parentTokenId: The parent token ID for delegated tokens.
/// - allowDelegation: Whether delegation is allowed.
/// - maxDelegationDepth: Maximum delegation depth.
/// - minTtlReduction: Minimum TTL reduction for delegation (seconds).
public init(
id: String,
public let maxDelegationDepth: UInt32
/// Minimum TTL reduction (in seconds) when delegating to child tokens.
public let minTtlReduction: Int64
/// Creates a new Arsenal ACT.
///
/// - Parameters:
/// - id: Unique token identifier.
/// - agentDid: The agent's OAS DID.
/// - issuer: The issuer identifier.
/// - audience: The audience identifier.
/// - capabilities: The capabilities granted.
/// - scopes: The scope strings granted.
/// - issuedAt: When the token was issued.
/// - notBefore: When the token becomes valid.
/// - expiresAt: When the token expires, or nil.
/// - parentTokenId: The parent token ID for delegated tokens.
/// - allowDelegation: Whether delegation is allowed.
/// - maxDelegationDepth: Maximum delegation depth.
/// - minTtlReduction: Minimum TTL reduction for delegation (seconds).
public init(
id: String,
agentDid: String,
issuer: String,
audience: String,
public let minTtlReduction: Int64
/// Creates a new Arsenal ACT.
///
/// - Parameters:
/// - id: Unique token identifier.
/// - agentDid: The agent's OAS DID.
/// - issuer: The issuer identifier.
/// - audience: The audience identifier.
/// - capabilities: The capabilities granted.
/// - scopes: The scope strings granted.
/// - issuedAt: When the token was issued.
/// - notBefore: When the token becomes valid.
/// - expiresAt: When the token expires, or nil.
/// - parentTokenId: The parent token ID for delegated tokens.
/// - allowDelegation: Whether delegation is allowed.
/// - maxDelegationDepth: Maximum delegation depth.
/// - minTtlReduction: Minimum TTL reduction for delegation (seconds).
public init(
id: String,
agentDid: String,
issuer: String,
audience: String,
capabilities: [Capability],
scopes: [String],
issuedAt: Timestamp;
public init(
id: String,
agentDid: String,
issuer: String,
audience: String,
capabilities: [Capability],
scopes: [String],
issuedAt: Timestamp;
public var isExpired: Bool
public var remainingTtlSeconds: Int64?
public func verifyACT(_ act: ArsenalACT) throws
public func extractScopes(_ act: ArsenalACT) -> [String]
public func actAllowsScope(_ act: ArsenalACT, scope: String) throws -> BoolDelegation.swift
Read declaration text · 11 declaration entries
public struct DelegationRequest: Sendable
public let parentACT: ArsenalACT
/// The parent agent's OAS DID.
public let parentDid: String
/// The child agent's OAS DID.
public let childDid: String
/// The capabilities requested for the child agent.
///
/// Must be a subset of the parent's capabilities.
public let requestedCapabilities: [Capability]
/// The scope strings requested for the child agent.
///
/// Must be a subset of the parent's scopes.
public let requestedScopes: [String]
/// Creates a new delegation request.
///
/// - Parameters:
/// - parentACT: The parent agent's Arsenal ACT.
/// - parentDid: The parent agent's OAS DID.
/// - childDid: The child agent's OAS DID.
/// - requestedCapabilities: The capabilities requested for the child.
/// - requestedScopes: The scope strings requested for the child.
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
public let parentDid: String
/// The child agent's OAS DID.
public let childDid: String
/// The capabilities requested for the child agent.
///
/// Must be a subset of the parent's capabilities.
public let requestedCapabilities: [Capability]
/// The scope strings requested for the child agent.
///
/// Must be a subset of the parent's scopes.
public let requestedScopes: [String]
/// Creates a new delegation request.
///
/// - Parameters:
/// - parentACT: The parent agent's Arsenal ACT.
/// - parentDid: The parent agent's OAS DID.
/// - childDid: The child agent's OAS DID.
/// - requestedCapabilities: The capabilities requested for the child.
/// - requestedScopes: The scope strings requested for the child.
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
requestedCapabilities: [Capability],
requestedScopes: [String]
public let childDid: String
/// The capabilities requested for the child agent.
///
/// Must be a subset of the parent's capabilities.
public let requestedCapabilities: [Capability]
/// The scope strings requested for the child agent.
///
/// Must be a subset of the parent's scopes.
public let requestedScopes: [String]
/// Creates a new delegation request.
///
/// - Parameters:
/// - parentACT: The parent agent's Arsenal ACT.
/// - parentDid: The parent agent's OAS DID.
/// - childDid: The child agent's OAS DID.
/// - requestedCapabilities: The capabilities requested for the child.
/// - requestedScopes: The scope strings requested for the child.
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
requestedCapabilities: [Capability],
requestedScopes: [String]
)
public let requestedCapabilities: [Capability]
/// The scope strings requested for the child agent.
///
/// Must be a subset of the parent's scopes.
public let requestedScopes: [String]
/// Creates a new delegation request.
///
/// - Parameters:
/// - parentACT: The parent agent's Arsenal ACT.
/// - parentDid: The parent agent's OAS DID.
/// - childDid: The child agent's OAS DID.
/// - requestedCapabilities: The capabilities requested for the child.
/// - requestedScopes: The scope strings requested for the child.
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
requestedCapabilities: [Capability],
requestedScopes: [String]
)
public let requestedScopes: [String]
/// Creates a new delegation request.
///
/// - Parameters:
/// - parentACT: The parent agent's Arsenal ACT.
/// - parentDid: The parent agent's OAS DID.
/// - childDid: The child agent's OAS DID.
/// - requestedCapabilities: The capabilities requested for the child.
/// - requestedScopes: The scope strings requested for the child.
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
requestedCapabilities: [Capability],
requestedScopes: [String]
)
public init(
parentACT: ArsenalACT,
parentDid: String,
childDid: String,
requestedCapabilities: [Capability],
requestedScopes: [String]
)
public struct DelegationManager: Sendable
public init()
public func delegateCapabilities(_ request: DelegationRequest) throws -> ArsenalACT
public func delegateCapabilities(_ request: DelegationRequest) throws -> ArsenalACTToolAuth.swift
Read declaration text · 14 declaration entries
public struct ToolAuthorizationRequest: Sendable
public let agentDid: AgentDid
/// The tool being invoked.
public let toolName: String
/// The tool tier.
public let toolTier: ToolTier
/// The ACT to check against, or `nil` for legacy mode.
public let act: ArsenalACT?
/// Creates a new tool authorization request.
///
/// - Parameters:
/// - agentDid: The agent's OAS DID.
/// - toolName: The tool being invoked.
/// - toolTier: The tool tier classification.
/// - act: The Arsenal ACT to check, or `nil` for legacy mode.
public init(agentDid: AgentDid, toolName: String, toolTier: ToolTier, act: ArsenalACT?)
public let toolName: String
/// The tool tier.
public let toolTier: ToolTier
/// The ACT to check against, or `nil` for legacy mode.
public let act: ArsenalACT?
/// Creates a new tool authorization request.
///
/// - Parameters:
/// - agentDid: The agent's OAS DID.
/// - toolName: The tool being invoked.
/// - toolTier: The tool tier classification.
/// - act: The Arsenal ACT to check, or `nil` for legacy mode.
public init(agentDid: AgentDid, toolName: String, toolTier: ToolTier, act: ArsenalACT?)
public let toolTier: ToolTier
/// The ACT to check against, or `nil` for legacy mode.
public let act: ArsenalACT?
/// Creates a new tool authorization request.
///
/// - Parameters:
/// - agentDid: The agent's OAS DID.
/// - toolName: The tool being invoked.
/// - toolTier: The tool tier classification.
/// - act: The Arsenal ACT to check, or `nil` for legacy mode.
public init(agentDid: AgentDid, toolName: String, toolTier: ToolTier, act: ArsenalACT?)
public let act: ArsenalACT?
/// Creates a new tool authorization request.
///
/// - Parameters:
/// - agentDid: The agent's OAS DID.
/// - toolName: The tool being invoked.
/// - toolTier: The tool tier classification.
/// - act: The Arsenal ACT to check, or `nil` for legacy mode.
public init(agentDid: AgentDid, toolName: String, toolTier: ToolTier, act: ArsenalACT?)
public init(agentDid: AgentDid, toolName: String, toolTier: ToolTier, act: ArsenalACT?)
public enum ToolAuthorizationDecision: Sendable, Equatable
public var isAllowed: Bool
public var isDenied: Bool
public var isLegacyMode: Bool
public struct ToolAuthorizer: Sendable
public init()
public func authorize(_ request: ToolAuthorizationRequest) throws -> ToolAuthorizationDecision
public func authorizeToolInvocation(_ request: ToolAuthorizationRequest) throws -> ToolAuthorizationDecision