@lancedb/lancedb • Docs
@lancedb/lancedb / NativeOAuthConfig
Interface: NativeOAuthConfig¶
OAuth configuration for LanceDB authentication.
This is the generated napi-rs binding shape. TypeScript users should prefer
the public OAuthConfig type exported from @lancedb/lancedb.
All token acquisition and refresh is handled in the Rust layer.
Properties¶
audience?¶
Optional provider-specific audience for authorization and token requests.
callbackPort?¶
Port for the authorization_code loopback callback server.
clientAuthMethod?¶
How the client authenticates to the token endpoint: "none", "client_secret_basic", or "client_secret_post". Defaults to "client_secret_basic" when a client secret is set, and "none" for public clients.
clientId¶
Application / Client ID.
clientSecret?¶
Client secret (required for client_credentials).
flow?¶
Authentication flow: "client_credentials", "authorization_code", "device_code", or "azure_managed_identity"
issuerUrl¶
OIDC issuer URL or OAuth authority URL.
For Azure: https://login.microsoftonline.com/{tenant_id}/v2.0
managedIdentityClientId?¶
Client ID for user-assigned managed identity (azure_managed_identity).
redirectUri?¶
Loopback redirect URI for authorization_code.
refreshBufferSecs?¶
Seconds before expiry to trigger proactive refresh (default: 300). Keep this well below the token TTL; if it is greater than or equal to the TTL, each request refreshes the token.
resource?¶
Optional resource indicator for authorization and token requests.
scopes¶
OAuth scopes to request. For Azure managed identity, exactly one scope
or resource is required. For example: ["api://{app_id}/.default"]
tokenCache?¶
Opt in to the persistent token cache so short-lived processes reuse one session. Only refresh tokens are persisted.
usePkce?¶
Whether authorization_code uses S256 PKCE (default: true).