Verso Fetch uses two authentication mechanisms depending on the context.
JWT links (user-facing flows)
The connect and manage pages are accessed via signed JWT links. Your backend generates a short-lived token using signLink() from @verso/core.
SignLinkOptions
SignedLink return type
Example
Security properties
- Algorithm: HS256 (HMAC-SHA256)
- Max TTL: 15 minutes. Tokens with longer expiration are rejected.
- Single-use: Each token contains a unique
jti (JWT ID). The server inserts it into a used_jti table — duplicate usage is rejected with 403.
- Scope validation: Requested scopes are checked against your app’s
allowed_scopes configuration.
Available scopes
Bearer tokens (server-to-server)
The API endpoints (/api/conversations, /api/ingest-export, /api/purge) authenticate via your app secret as a Bearer token.
Authentication uses timing-safe comparison against your app’s secret stored in the vault.
Rate limiting
API endpoints are rate-limited to 60 requests per minute per app. The rate limiter is database-backed (atomic counter per app per minute bucket).
Rate limit headers are included in every response:
Never expose your app secret in client-side code. All API calls should be
made from your backend.