SessionManager
SessionManager provides stateless HMAC-SHA256 token generation and validation
for SWAIG function call authentication. Tokens encode a call ID, function name,
expiry, and nonce, signed with a shared secret. It also supports per-session
metadata storage with automatic cleanup.
Constructor
tokenExpirySecs
Token validity duration in seconds.
secretKey
HMAC signing secret. A random 32-byte key is generated if omitted.
Properties
debugMode
When true, debugToken
decodes token internals for inspection. When false, debugToken returns
{ error: "debug mode not enabled" }. Set this to true at runtime only when
you need to inspect token contents.