module documentation
Remove sensitive parts from tokens.
This module masks signatures and other sensitive token parts. It keeps useful nonsensitive parts visible. It supports Nebius IAM tokens and JWT tokens. Token-version definitions specify prefixes, delimiters, and signature positions.
| Class | |
Identify token versions from a predefined mapping. |
| Class | |
Mask sensitive token parts according to the token version. |
| Class | |
Describe the structure of a token version. |
| Class | |
Define the interface that identifies a token version. |
| Function | sanitize |
Mask the complete payload of a token that has no signature. |
| Function | sanitize |
Mask an unrecognized token completely. |
| Constant | ACCESS |
Supported access-token formats. |
| Constant | CREDENTIALS |
Supported credential formats. |
| Constant | MASK |
The mask printed instead of sensitive parts of tokens. |
| Constant | MAX |
Maximum length of visible payload before masking. |
| Constant | NO |
Constant indicating no signature position in the token. |
Supported access-token formats.
The keys are version names. The values describe each format.
| Value |
|
Supported credential formats.
The mapping contains all access-token formats, DE1, and JWT.
| Value |
|