Skip to main content
Verso Fetch uses two authentication mechanisms depending on the context. The connect and manage pages are accessed via signed JWT links. Your backend generates a short-lived token using signLink() from @verso/core.

SignLinkOptions

Example

Security properties

  • Algorithm: HS256 (HMAC-SHA256)
  • Max TTL: 15 minutes. Tokens with longer expiration are rejected.
  • Single-use: Each token contains a unique jti (JWT ID). The server inserts it into a used_jti table — duplicate usage is rejected with 403.
  • Scope validation: Requested scopes are checked against your app’s allowed_scopes configuration.

Available scopes

Bearer tokens (server-to-server)

The API endpoints (/api/conversations, /api/ingest-export, /api/purge) authenticate via your app secret as a Bearer token.
Authentication uses timing-safe comparison against your app’s secret stored in the vault.

Rate limiting

API endpoints are rate-limited to 60 requests per minute per app. The rate limiter is database-backed (atomic counter per app per minute bucket). Rate limit headers are included in every response:
Never expose your app secret in client-side code. All API calls should be made from your backend.