Verifies tokens LangSmith signs for code running in or behind a sandbox.
Keys are fetched from LangSmith's JWKS endpoint and cached.
Example:
verifier = SandboxTokenVerifier()
user = verifier.verify_user_token( request.headers[USER_TOKEN_HEADER], audience=request.headers["Host"] )
callback = verifier.verify_callback( body=await request.body(), signature=request.headers[CALLBACK_SIGNATURE_HEADER], aud="https://example.com/sandbox-callback", )
HTTP timeout in seconds for fetching the JWKS.
Allow fetching the JWKS over plain HTTP from a non-loopback host. Anyone who can tamper with that traffic can forge tokens this verifier accepts.