Skip to navigation

Validate a token against the expected call ID and function name. Checks the HMAC signature, expiration, function name match, and call ID match.

Parameters

callId
stringRequired

The expected call ID.

functionName
stringRequired

The expected function name.

token
stringRequired

The base64url-encoded token to validate.

Returns

boolean — true if the token is valid and not expired.

Example

import { SessionManager } from '@signalwire/sdk';
const sm = new SessionManager();
const token = sm.generateToken('get_weather', 'call-abc123');
const valid = sm.validateToken('call-abc123', 'get_weather', token);
console.log('Valid:', valid); // true