# `verae-zapier-middleware/lib/tokens` **Package:** `verae-zapier-middleware` **Source:** `packages/verae-zapier-middleware/src/lib/tokens.js` **Lines:** 98 ## What this module is Implementation module in `verae-zapier-middleware`. The tables below are extracted from the source (signatures + JSDoc). ## Exports `issueSessionToken`, `parseSessionToken`, `generateApiKey`, `isApiKey`, `extractBearerToken` ## Types / interfaces / classes _None extracted._ ## Functions | Name | Parameters | Param types (JSDoc) | Returns | Calls (same file / helpers) | |------|------------|---------------------|---------|-----------------------------| | `sign` | `payload` | payload: `string` | `string` | see Call graph | | `issueSessionToken` | `{ tenantId, veraeToken, expiresAt }` | params: `object`, params.tenantId: `string`, params.veraeToken: `string`, params.expiresAt: `string` | `string` — Token string starting with `zmt_` | see Call graph | | `parseSessionToken` | `token` | token: `string` | `{ tenantId: string, veraeToken: string, expiresAt?: string, nonce?: string ` — |null} | see Call graph | | `generateApiKey` | `(none)` | — | `string` | see Call graph | | `isApiKey` | `value` | value: `unknown` | `boolean` | see Call graph | | `extractBearerToken` | `header` | header: `string|undefined` | `string|null` | see Call graph | ## What it imports / requires - `node:crypto` - `../config.js` ## Call graph (identifiers invoked) `sign`, `createHmac`, `update`, `digest`, `issueSessionToken`, `from`, `stringify`, `randomBytes`, `toString`, `parseSessionToken`, `startsWith`, `slice`, `lastIndexOf`, `timingSafeEqual`, `parse`, `key`, `generateApiKey`, `isApiKey`, `extractBearerToken`, `match` Each identifier is a call site in this file. Follow the import list to see the defining module; open that module’s MD for parameter and return types. ## Return values (how to read this) - HTTP route handlers return Express `res.json(...)` bodies (see route docs). - Zapier `perform` functions return a **single object** (creates) or an **array** (triggers/searches). - Pricing functions return integer **cents** on `Quote.totalCents`.