the request
the response, which a refusal is sent on
Optionalwhere: string
the endpoint, named in the log and refusals
Optionaloptions: any
audience, requireVerified and stepUp, which only RFC
9470's stand-in resource passes
{ accessToken, claims, scheme, jkt, verified, dpop }, or null
once a refusal has been sent
Checks the access token on a protected endpoint, Bearer or DPoP, and sends the refusal itself when it fails; a step-up challenge is asked last.