1: <?php
2:
3: declare(strict_types=1);
4:
5: /**
6: * This file is part of the Nexus MCP SDK package.
7: *
8: * (c) 2026 John Paul E. Balandan, CPA <paulbalandan@gmail.com>
9: *
10: * For the full copyright and license information, please view
11: * the LICENSE file that was distributed with this source code.
12: */
13:
14: namespace Nexus\Mcp\Server\Auth;
15:
16: use Nexus\Mcp\Core\Auth\VerifiedAccessToken;
17:
18: /**
19: * Turns a bearer token into what it grants. The SDK ships no signature or introspection machinery, so a host
20: * supplies the verification its authorization server calls for.
21: *
22: * An implementation owns the whole of token validation, signature or introspection and expiry included, and
23: * rejects a token it cannot verify by returning `null`. Only two checks are not its job:
24: * `BearerAuthenticationMiddleware` binds the returned audience to this server and enforces the scopes the
25: * endpoint requires.
26: *
27: * @see https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization#token-handling
28: */
29: interface AccessTokenValidatorInterface
30: {
31: public function validate(string $token): ?VerifiedAccessToken;
32: }
33: