Public declaration syntax from forge-ts/packages/forge-auth/src/capability.ts Original source SHA-256: fa41d8819b1680b5fcae3f0ae4bab5353de32cfff73b1606cb10907b488012e7 Function bodies and constant values are omitted. This is not the complete implementation. Source line 37 export interface AgentCapabilityToken { /** The unique token identifier. */ readonly id: string; /** The agent DID this token is for. */ readonly subject: string; /** The token issuer. */ readonly issuer: string; /** The intended audience. */ readonly audience: string; /** The granted scopes in 'service:resource:action' format. */ readonly scopes: readonly string[]; /** The ISO 8601 timestamp when the token was issued. */ readonly issuedAt: string; /** The ISO 8601 timestamp after which the token is valid. */ readonly notBefore: string; /** The ISO 8601 timestamp at which the token expires. */ readonly expiresAt: string; /** Optional delegation constraints. */ readonly delegation?: DelegationConstraints; } Source line 61 export interface DelegationConstraints { /** Whether delegation is allowed. */ readonly allowDelegation: boolean; /** Optional list of allowed delegate agent IDs. Empty = any agent. */ readonly allowedDelegates: readonly string[]; /** Minimum TTL reduction in seconds when delegating. */ readonly minTtlReduction: number; /** Maximum delegation depth. */ readonly maxDelegationDepth: number; } Source line 93 export function verifyAct(act: AgentCapabilityToken): void; Source line 147 export function extractScopes(act: AgentCapabilityToken): string[]; Source line 174 export function actAllowsScope(act: AgentCapabilityToken, scope: string): boolean; Source line 200 export function scopeImplies(granted: string, requested: string): boolean;