Skip to content

@dukkan.one/app-sdk/tokens/postgres

A TokenStore over a postgres.js client: row lock per install for refreshes, sealed columns, update-then-insert saves.

Package
@dukkan.one/app-sdk@0.3.0
API revision
2026-09-10
Import
import { … } from "@dukkan.one/app-sdk/tokens/postgres"
On this page

Functions

createPostgresTokenStore#

function createPostgresTokenStore(options: PostgresTokenStoreOptions): TokenStore

Postgres token store. The refresh lock is select ... for update on the install row inside a transaction, so a second instance blocks on the row until the first has saved the rotated pair and then reads the fresh row.

Keep the transaction short: the SDK holds it only for the token endpoint round trip (bounded by its timeout). On a transaction-mode pooler (pgbouncer :6543) that is fine; never run other work inside the lock.

Interfaces

PostgresLikeSql#

interface PostgresLikeSql

The slice of a postgres.js client the adapter uses. Any client with a tagged-template sql, sql.begin, and identifier interpolation (sql(name)) fits; the first-party apps pass their postgres instance.

Members
NameTypeDescription
beginRequired<T>(fn: (tx: PostgresLikeSql) => Promise<T>): Promise<T>

PostgresTokenColumns#

interface PostgresTokenColumns

Column names of the install table; every key has a default matching the reference schema.

Members
NameTypeDescription
installIdRequiredstring
storeIdRequiredstring
accessTokenRequiredstring
accessExpiresAtRequiredstring
refreshTokenRequiredstring
refreshExpiresAtRequiredstring
scopesRequiredstring
reconnectRequiredRequiredstring
updatedAtRequiredstring

PostgresTokenStoreOptions#

interface PostgresTokenStoreOptions

Configuration of createPostgresTokenStore: the postgres.js client, the table and column names, and the sealer.

Members
NameTypeDescription
sqlRequiredPostgresLikeSql
tablestring | undefined

Table holding one row per install (default installs).

columnsPartial<PostgresTokenColumns> | undefined

Column names; defaults match the reference schema in the docs.

sealerSecretSealer | undefined
onNoSealer((message: string) => void) | undefined

Called once when no sealer is configured (default: console.warn).