1: <?php
2:
3: declare(strict_types=1);
4:
5: /**
6: * This file is part of the Nexus MCP SDK package.
7: *
8: * (c) 2026 John Paul E. Balandan, CPA <paulbalandan@gmail.com>
9: *
10: * For the full copyright and license information, please view
11: * the LICENSE file that was distributed with this source code.
12: */
13:
14: namespace Nexus\Mcp\Client\Auth;
15:
16: /**
17: * Holds the access tokens a client has obtained, keyed by the MCP server each token is bound to. The issuer
18: * that minted a token travels on the token itself. Implementations are responsible for storing tokens
19: * confidentially.
20: *
21: * @see https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization/security-considerations#token-theft
22: */
23: interface TokenStoreInterface
24: {
25: /**
26: * @param string $resource Canonical URI of the MCP server the token is bound to
27: */
28: public function read(string $resource): ?AccessToken;
29:
30: public function write(string $resource, AccessToken $token): void;
31:
32: public function forget(string $resource): void;
33: }
34: