Skip to content

fix: don't encode validity_in_seconds in user/call token payloads - #366

Merged
oliverlaz merged 1 commit into
mainfrom
fix/token-payload-validity-in-seconds
Oct 6, 2026
Merged

oliverlaz merged 1 commit into
mainfrom
fix/token-payload-validity-in-seconds

Conversation

@oliverlaz

@oliverlaz oliverlaz commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Problem

generateUserToken (and generateCallToken, which delegates to it) passed the caller's payload object straight to jwt.sign. As a result, validity_in_seconds — an SDK option that only exists to compute exp — was encoded into every token where it was provided, inflating the payload for no reason. This includes the StreamVideoClient realtime agent path, which forwards validity_in_seconds.

Both generateUserToken and generatePermanentUserToken also mutated the caller's payload by writing iat/exp onto it.

Changes

  • generateUserToken destructures validity_in_seconds out of the payload, uses it to compute exp, and signs a fresh object containing only the remaining claims plus iat/exp. A default token now contains just user_id, iat, exp.
  • generatePermanentUserToken builds a new object instead of mutating the input.
  • No signature changes. Only observable behavior change: the input payload is no longer mutated.

Tests

Added to __tests__/create-token.test.ts (all failed before the fix):

  • user token does not contain validity_in_seconds; default claims are exactly user_id, iat, exp
  • the caller's payload object is not mutated
  • call token does not contain validity_in_seconds, and exp - iat still matches the requested validity

validity_in_seconds is an SDK option used only to compute exp, but it was
passed through to jwt.sign and ended up in the token. Strip it before
signing, and stop mutating the caller's payload object.

Co-Authored-By: Claude <noreply@anthropic.com>
@oliverlaz
oliverlaz requested a review from szuperaz as a code owner October 6, 2026 08:34
@oliverlaz
oliverlaz merged commit e74fad5 into main Oct 6, 2026
8 of 11 checks passed
@oliverlaz
oliverlaz deleted the fix/token-payload-validity-in-seconds branch October 6, 2026 14:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants