true (allow) or false (deny). If any hook denies the request, the operation is rejected before risk assessment or policy evaluation begins.
Built-in Auth Hooks
BearerTokenAuth
Validates theactor_id in the operation context against a set of known tokens. Useful for service-to-service authentication where each caller has a static bearer token.
- Python
- TypeScript
ScopeAuth
Grants access based on tenant, project, and agent scope. You register which actor IDs are allowed to operate within specific scopes, and the hook enforces those boundaries at request time.- Python
- TypeScript
CompositeAuth
Chains multiple auth hooks together using AND logic. Every hook must returntrue for the operation to proceed. This lets you layer authentication (token validation) with authorization (scope checks).
- Python
- TypeScript
Attaching Auth to Memproof
Pass the auth hook when constructing your Memproof instance. The hook is called before every operation enters the pipeline.- Python
- TypeScript
Writing a Custom Auth Hook
Any function that accepts the operation context and scope and returns a boolean can serve as an auth hook. This makes it straightforward to integrate with external identity providers, JWTs, or custom RBAC systems.- Python
- TypeScript