Skip to content

feat(providers): add multiple tokens to one request - #4047

Open
shiju-nv wants to merge 2 commits into
mainfrom
feat/providers-multiple-dynamic-grants
Open

shiju-nv wants to merge 2 commits into
mainfrom
feat/providers-multiple-dynamic-grants

Conversation

@shiju-nv

@shiju-nv shiju-nv commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

An API behind an access gateway may need two tokens on the same request: a gateway access token in X-Gateway-Token and the API's own bearer token in Authorization. OpenShell previously picked just one matching dynamic grant. This change lets the Supervisor get a separate token for each header and send the request only when every token is ready.

Related Issue

Fixes #3320.

Changes

  • Let the gateway accept multiple grants for the same endpoint when they fill different headers. Each grant keeps its own token endpoint, audience, scopes and cache settings.
  • Pick the most specific match for each header, ignoring header-name casing. If different credentials tie for the same header, reject the request.
  • Get and validate every selected token before changing or forwarding the request. If any grant fails, the request doesn't go out.
  • Replace any agent-supplied values in those headers. Keep raw issuer errors out of logs and returned errors.
  • Update the provider docs and add tests for separate token caches, header replacement and failure handling. Cache entries stay separate across provider instances and revisions.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated
  • E2E tests added/updated (if applicable)

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable): the provider-profile reference explains the new behavior.

Select the most-specific grant independently for each protected header,
preserving each credential's issuer, audience and cache identity. Resolve
all selected grants before rewriting the request, replace agent-supplied
header copies, and fail closed on collisions or acquisition failures.

Allow distinct-header compositions in gateway validation and redact raw
issuer errors. Cover independent cache entries, atomic TLS relay failure,
header replacement and concurrent request isolation; document the profile
contract.

Fixes #3320

Signed-off-by: Shiju <shiju@nvidia.com>
Use if-let for a grant result whose error payload is deliberately ignored,
and name the empty query map type in the regression fixture. Preserve grant
acquisition, failure redaction and request atomicity. Update the token-exchange
failure test to require the sanitized error instead of raw issuer text.

Signed-off-by: Shiju <shiju@nvidia.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(providers): support multiple dynamic credential injections on one request

1 participant