Verifies tokens LangSmith signs for code running in or behind a sandbox.
Keys are fetched from LangSmith's JWKS endpoint and cached. Requires Web Crypto Ed25519 support (Node.js 20+, Deno, Bun, Cloudflare Workers).
class SandboxTokenVerifierconst verifier = new SandboxTokenVerifier();
// In an app served from a LangSmith-login service URL:
const user = await verifier.verifyUserToken(
req.headers.get(USER_TOKEN_HEADER)!,
{ audience: req.headers.get("host")! }
);
// In a proxy callback endpoint:
const callback = await verifier.verifyCallback({
body: await req.text(),
signature: req.headers.get(CALLBACK_SIGNATURE_HEADER)!,
aud: "https://example.com/sandbox-callback",
});Verify a proxy callback request and return its parsed payload.
Verify the X-Langsmith-User-Token header of a service URL request.
LangSmith sets this header only for service URLs that use LangSmith login.
Code that knows it is running in a sandbox can instead trust the unsigned
X-Langsmith-User-Id and X-Langsmith-User-Email headers, which the
sandbox runtime strips from inbound requests and sets itself; verify this
token when that is not guaranteed.