> Fetch clean Markdown by appending `.md` to any page URL under https://signalwire.com/docs or requesting it with the HTTP header `Accept: text/markdown`. The root index at https://signalwire.com/docs/llms.txt lists the available documentation indexes. # AuthHandler > Multi-method authentication handler with timing-safe credential comparison. [validate]: /docs/server-sdks/reference/typescript/agents/configuration/auth-handler/validate [middleware]: /docs/server-sdks/reference/typescript/agents/configuration/auth-handler/middleware [hasbearerauth]: /docs/server-sdks/reference/typescript/agents/configuration/auth-handler/has-bearer-auth [hasapikeyauth]: /docs/server-sdks/reference/typescript/agents/configuration/auth-handler/has-api-key-auth [hasbasicauth]: /docs/server-sdks/reference/typescript/agents/configuration/auth-handler/has-basic-auth `AuthHandler` provides a unified authentication layer supporting Bearer tokens, API keys, and HTTP Basic Auth. All credential comparisons use constant-time algorithms to prevent timing attacks. It can be used as Hono middleware or as a standalone request validator. ```typescript {3-6} import { AuthHandler } from '@signalwire/sdk'; const auth = new AuthHandler({ bearerToken: 'my-secret-token', apiKey: 'my-api-key', }); ``` ## **Constructor** **`config`** `AuthConfig` — required Authentication configuration object with the following optional fields: --- **`config.bearerToken`** `string` Bearer token matched against the `Authorization: Bearer ` header. --- **`config.apiKey`** `string` API key matched against the `X-Api-Key` header (or the custom header named by `config.apiKeyHeader`). --- **`config.apiKeyHeader`** `string` — default: 'X-Api-Key' Custom header name to use for API key lookup instead of the default `X-Api-Key`. Lookup is case-insensitive. --- **`config.basicAuth`** `[string, string]` Basic auth credentials as a `[username, password]` tuple. --- **`config.customValidator`** `(request: { headers, method, url }) => boolean | Promise` Custom validator function. Return `true` to allow the request. --- **`config.allowUnauthenticated`** `boolean` When explicitly set to `false`, deny requests if no auth methods are configured. By default, unauthenticated access is allowed when no methods are set. --- ## **Methods** #### [validate](/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/validate) Validate request headers against all configured auth methods. #### [middleware](/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/middleware) Create a Hono-compatible middleware that rejects unauthorized requests. #### [expressMiddleware](/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/express-middleware) Create an Express/Connect-compatible middleware adapter. #### [verifyBasicAuth](/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/verify-basic-auth) Verify a username/password pair with constant-time comparison. #### [verifyBearerToken](/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/verify-bearer-token) Verify a Bearer token with constant-time comparison. #### [verifyApiKey](/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/verify-api-key) Verify an API key with constant-time comparison. #### [getAuthInfo](/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/get-auth-info) Get metadata describing the enabled auth methods. #### [hasBearerAuth](/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/has-bearer-auth) Check whether Bearer token authentication is configured. #### [hasApiKeyAuth](/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/has-api-key-auth) Check whether API key authentication is configured. #### [hasBasicAuth](/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/has-basic-auth) Check whether Basic authentication is configured. ## **Example** ```typescript {4-7,10} import { AuthHandler } from '@signalwire/sdk'; const auth = new AuthHandler({ bearerToken: process.env.AUTH_TOKEN, basicAuth: ['admin', 'secret'], apiKey: process.env.API_KEY, }); // Check which methods are configured console.log('Bearer:', auth.hasBearerAuth()); // true console.log('API Key:', auth.hasApiKeyAuth()); // true console.log('Basic:', auth.hasBasicAuth()); // true // Validate incoming request headers const isValid = await auth.validate({ authorization: 'Bearer my-secret-token', }); console.log('Valid:', isValid); ``` > Multi-method authentication handler with timing-safe credential comparison. ## Docs - [expressMiddleware](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/express-middleware.md): Create an Express/Connect-compatible middleware adapter. - [getAuthInfo](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/get-auth-info.md): Get structured metadata describing the enabled authentication methods. - [hasApiKeyAuth](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/has-api-key-auth.md): Check whether API key authentication is configured. - [hasBasicAuth](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/has-basic-auth.md): Check whether Basic authentication is configured. - [hasBearerAuth](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/has-bearer-auth.md): Check whether Bearer token authentication is configured. - [middleware](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/middleware.md): Create a Hono-compatible middleware that rejects unauthorized requests. - [validate](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/validate.md): Validate request headers against all configured authentication methods. - [verifyApiKey](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/verify-api-key.md): Verify an API key against the configured key. - [verifyBasicAuth](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/verify-basic-auth.md): Verify a username/password pair against the configured Basic Auth credentials. - [verifyBearerToken](https://signalwire.com/docs/server-sdks/reference/typescript/agents/configuration/auth-handler/verify-bearer-token.md): Verify a Bearer token against the configured token.