Skip to main content

Module auth

Module auth 

Source
Expand description

Connection authorization: the per-session token + a constant-time header check.

The security boundary is the loopback bind (127.0.0.1) plus this token: the server writes a fresh token into the discovery lockfile, and an attaching agent must echo it in the x-claude-code-ide-authorization handshake header. The token is compared in constant time so a local attacker can’t time-side-channel it byte by byte.

Constants§

AUTH_HEADER
The handshake header the agent must present, carrying the token read from the discovery lockfile. Matches the VS Code IDE-integration contract so the stock claude CLI authorizes unchanged.

Functions§

generate_token
Mint a fresh random auth token: 16 CSPRNG bytes rendered as 32 hex characters. Loopback bind + this token are the only security boundary, so the token must be unpredictable.
header_matches
Whether the provided header value matches the expected token, compared in constant time. Returns false immediately on length mismatch — tokens are fixed-length, so length is not secret.