Expand description
Connection authorization: the per-session token + a constant-time header check.
The security boundary is the loopback bind (127.0.0.1) plus this
token: the server writes a fresh token into the discovery lockfile,
and an attaching agent must echo it in the
x-claude-code-ide-authorization handshake header. The token is
compared in constant time so a local attacker can’t time-side-channel
it byte by byte.
Constants§
- AUTH_
HEADER - The handshake header the agent must present, carrying the token read
from the discovery lockfile. Matches the VS Code IDE-integration
contract so the stock
claudeCLI authorizes unchanged.
Functions§
- generate_
token - Mint a fresh random auth token: 16 CSPRNG bytes rendered as 32 hex characters. Loopback bind + this token are the only security boundary, so the token must be unpredictable.
- header_
matches - Whether the provided header value matches the expected token, compared
in constant time. Returns
falseimmediately on length mismatch — tokens are fixed-length, so length is not secret.