SandboxTokenVerifier verifies tokens LangSmith signs for code running in or.
type SandboxTokenVerifier structSandboxTokenVerifier verifies tokens LangSmith signs for code running in or behind a sandbox: the X-Langsmith-User-Token header of service URL requests and the X-LangSmith-Signature-JWT header of proxy callbacks. Keys are fetched from LangSmith's JWKS endpoint and cached. It is safe for concurrent use.
Code that knows it is running in a sandbox can instead trust the unsigned X-Langsmith-User-Id and X-Langsmith-User-Email headers on requests that arrive through the service URL, which the sandbox runtime strips from inbound requests and sets itself. TCP tunnels and other processes in the sandbox calling the port over localhost bypass that stripping.
VerifyUserToken verifies the X-Langsmith-User-Token header of a request made.
VerifyCallback verifies a proxy callback request and returns its parsed.