LangChain Reference home pageLangChain ReferenceLangChain Reference
  • GitHub
  • Main Docs
Deep Agents
LangChain
LangGraph
Integrations
LangSmith
  • Overview
  • Client
  • AsyncClient
  • Run Helpers
  • Run Trees
  • Evaluation
  • Schemas
  • Utilities
  • Wrappers
  • Anonymizer
  • Testing
  • Expect API
  • Middleware
  • Pytest Plugin
  • Deployment SDK
⌘I

LangChain Assistant

Ask a question to get started

Enter to send•Shift+Enter new line

Menu

OverviewClientAsyncClientRun HelpersRun TreesEvaluationSchemasUtilitiesWrappersAnonymizerTestingExpect APIMiddlewarePytest PluginDeployment SDK
Language
Theme
Pythonlangsmithsandbox_verifySandboxTokenVerifier
Classā—Since v0.14

SandboxTokenVerifier

Copy
SandboxTokenVerifier(
  self,
  *,
  api_url: Optional[str] = None,
  jwks_url: Optional

Constructors

Methods

View source on GitHub
[
str
]
=
None
,
timeout
:
float
=
10.0
,
allow_insecure_jwks
:
bool
=
False
)

Parameters

NameTypeDescription
api_urlOptional[str]
Default:None

LangSmith API URL whose origin serves the JWKS. Defaults to LANGSMITH_ENDPOINT.

jwks_urlOptional[str]
Default:None

Full JWKS URL; overrides api_url.

timeoutfloat
Default:10.0
allow_insecure_jwksbool
Default:False
constructor
__init__
NameType
api_urlOptional[str]
jwks_urlOptional[str]
timeoutfloat
allow_insecure_jwksbool
method
verify_user_token

Verify the X-Langsmith-User-Token header of a service URL request.

LangSmith sets this header only for service URLs that use LangSmith login. Code that knows it is running in a sandbox can instead trust the unsigned X-Langsmith-User-Id and X-Langsmith-User-Email headers, which the sandbox runtime strips from inbound requests and sets itself; verify this token when that is not guaranteed.

method
averify_user_token

Async version of :meth:verify_user_token.

method
verify_callback

Verify a proxy callback request and return its parsed payload.

method
averify_callback

Async version of :meth:verify_callback.

Verifies tokens LangSmith signs for code running in or behind a sandbox.

Keys are fetched from LangSmith's JWKS endpoint and cached.

Example:

verifier = SandboxTokenVerifier()

In an app served from a LangSmith-login service URL:

user = verifier.verify_user_token( request.headers[USER_TOKEN_HEADER], audience=request.headers["Host"] )

In a proxy callback endpoint:

callback = verifier.verify_callback( body=await request.body(), signature=request.headers[CALLBACK_SIGNATURE_HEADER], aud="https://example.com/sandbox-callback", )

HTTP timeout in seconds for fetching the JWKS.

Allow fetching the JWKS over plain HTTP from a non-loopback host. Anyone who can tamper with that traffic can forge tokens this verifier accepts.