Validates a token model (RFC 9767 section 2.1) before a format mints it and after a format reconstructs it.
The bearer flag and cnf must agree: a bound token has no bearer flag and a bearer token no cnf.
bearer
cnf
the token model
{ ok: true, model } with every optional member present as null, or a refusal
{ ok: true, model }
Validates a token model (RFC 9767 section 2.1) before a format mints it and after a format reconstructs it.
The
bearerflag andcnfmust agree: a bound token has nobearerflag and a bearer token nocnf.