Skip to content

fix(sso): return token_type, expires_in and profile.name from /sso/token - #130

Open
burkestar wants to merge 2 commits into
workos:mainfrom
burkestar:fix/sso-token-response-shape
Open

burkestar wants to merge 2 commits into
workos:mainfrom
burkestar:fix/sso-token-response-shape

Conversation

@burkestar

@burkestar burkestar commented Oct 6, 2026 •

Copy link
Copy Markdown

Fixes #129

Problem

The POST /sso/token response (authorization_code grant) has only access_token and profile. workos-python 10.5.0 parses it as SSOTokenResponse, which requires expires_in and declares token_type: "Bearer". Because expires_in is missing, client.sso.get_profile_and_token(code=...) fails, so SSO login can't be completed against the emulator.

Changes

  • Add token_type: "Bearer" and expires_in (600s, the spec's example) to the response, and sign the access token with that same lifetime.
  • Derive the spec-required, nullable Profile.name from first_name/last_name in formatSSOProfile, so /sso/profile gets it too.
  • Resolves a pre-existing issue where SSO tokens carried a 1-hour expiry that /sso/profile ignored

POST /sso/token returned only access_token and profile, so SDKs that parse
the spec's SsoTokenResponse (workos-python 10.5 get_profile_and_token) failed
on the missing expires_in, and then on the profile's missing name.

- Add token_type: "Bearer" and expires_in (600s, the spec's example) to the
  response, and sign the access token with that same lifetime.
- Derive the spec-required, nullable Profile.name from first_name/last_name
  in formatSSOProfile, so /sso/profile gets it too.

Fixes workos#129
@greptile-apps

greptile-apps Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium risk] Adds missing fields to the SSO token response.

The PR appears safe to merge; no new actionable issue was identified.

Summary

The PR adds the token fields and derived profile name needed by SSO SDK clients, then verifies bearer tokens before profile lookup so the reported lifetime is enforced.

  • Adds token-response, profile-name, and expiry tests.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[SSO authorization code] --> B["POST /sso/token"]
  B --> C[Signed bearer token and profile]
  C --> D["GET /sso/profile"]
  D --> E{Signature and expiry valid?}
  E -- Yes --> F[Return profile]
  E -- No --> G[401]
Loading

Reviews (2) · Last reviewed commit: "fix(sso): enforce the access token's exp..."

Comment thread src/workos/routes/sso.ts
/sso/profile resolved an issued token through the store before verifying it,
so a token kept working after the expires_in that /sso/token reported. Verify
the signature and exp first, for every token, then resolve the profile.

Adds the first /sso/profile tests: a token is accepted until expires_in has
passed and refused after, and an unsigned token is refused.
burkestar added a commit to burkestar/emulate that referenced this pull request Oct 6, 2026
burkestar added a commit to burkestar/emulate that referenced this pull request Oct 6, 2026
Fork build carrying workos#130 and workos#132 until upstream releases
them. The release-please manifest stays at 0.14.0 so upstream releases
merge cleanly.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

POST /sso/token response lacks expires_in and token_type, breaking workos-python 10.5 get_profile_and_token

1 participant