1: <?php
2:
3: declare(strict_types=1);
4:
5: /**
6: * This file is part of the Nexus MCP SDK package.
7: *
8: * (c) 2026 John Paul E. Balandan, CPA <paulbalandan@gmail.com>
9: *
10: * For the full copyright and license information, please view
11: * the LICENSE file that was distributed with this source code.
12: */
13:
14: namespace Nexus\Mcp\Server\Auth;
15:
16: use Nexus\Mcp\Core\Auth\VerifiedAccessToken;
17:
18: /**
19: * Turns a bearer token into what it grants, owning the whole of validation and returning `null` for anything
20: * it cannot verify, a token carrying no expiry or naming another resource included.
21: *
22: * @see https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization#token-handling
23: */
24: interface AccessTokenValidatorInterface
25: {
26: public function validate(string $token): ?VerifiedAccessToken;
27: }
28: