common access token
This module is available to use in your EdgeWorkers code bundles to enforce access policies efficiently, flexibly, and inter-operably. The common access token (CAT) module provides a simple, extensible, policy-bearing bearer token for content access.
You can create, verify, and renew CAT tokens using HS256 (HMAC SHA256), ES256 (ECDSA w/ SHA-256), and PS256 (RSASSA-PSS w/ SHA-256) algorithms.
- CAT tokens are a CWT based token. Refer to the CBOR Web Token (CWT) - (RFC8392) standards document for more information.
- CWT token signing and encryption is described in the CBOR Object Signing and Encryption (COSE) (rfc8152) standards document.
📘 The CAT module may change in the future
At this time, the module covers high level claims. You can extend it to other CAT claims in the spec as per your requirements.
The
encclaim is currently only supported using the A256-GCM encryption algorithm. You can adopt new algorithms as they become available in EdgeWorkers crypto module.
CAT
Constructor for new CAT object. It performs type checks on the catOptions object fields.
CATOptions Object
CATJSON Object
Contains CWT header and payload object.
Header
Payload
The set of claims from the CAT token as a JavaScript map.
ValidationResult Object
decode()
Performs the cbor decoding of the CAT token and returns the decoded CATJson. The CATJson contains the CAT claims set which can be used to perform validations if required.
Returns CATJson that contains protected headers, unprotected headers, and payload containing the claim set.
isCATWellFormed()
Performs type checks on each claim value from the claimset CAT payload.
Returns a ValidationResult that indicates the validation along with error message if validation fails.
async isCATAcceptable()
Validates that the CAT token is acceptable and that the request satisfies all supported claim set rules.
Returns a Promise indicating the validation status along with error message if validation fails.
If there is any claim present in the crit claim that are not supported by the CAT module, then this function will return a status of false with an error message.
Examples
CAT token generation example
This example demonstrates how you can use EdgeWorkers for CAT token generation.
Here is the request payload that is accepted for the below EdgeWorkers logic. The EdgeWorker reads the JSON payload and convert it to a CAT claims set (map) with integer keys.
CAT token verification and renewal example
This example demonstrates how you can use EdgeWorkers as a token verification service to verify and renew tokens.
📘 The
PMUSER_RENEWED_CATvariable holds the renewed token. The renewed token can be sent back to the client in response using the EdgeWorkersonClientResponseevent handler. It can also sent back using Property configuration rules without executing the EdgeWorker.
Limitations
Algorithm not provided externally
The CAT token must include the alg field as a part of CWT protected or unprotected header field when generated by any service. The EdgeWorkers cwt module relies on this field to determine which algorithm to use for token verification.
Missing client information in request object
As of now, the EdgeWorkers Request Object does not provide information such as network protocol or client IP. Review the examples below workarounds for this limitation.
Missing client information in request object
As of now, the Request Object does not provide information such as network protocol or client IP. However, you can copy the value from Built-in variables to User-defined variables using the Set variable behavior or Advanced behavior.
Review the examples below for workarounds for this limitation.
catalpn
To use the catalpn claim validation, you need to contact Akamai support. Ask your account representative to add the following Advanced behavior to your property configuration before the EdgeWorker behavior is executed.

Here is the XML for the Advanced behavior.
catnip claim
To use the catnip claim, you can add the following Set variable behavior to your property configuration before the EdgeWorker is executed.

Unsupported claims
The following claims are currently not supported by the CAT module.
- CAT token replay prevention. For example,
catreplay = 1. - CAT probability of rejection claim.
- CAT altitude claim.
- CAT TLS public key claim.
- DPoP claims.