Skip to content

client-certificate-auth API Reference


client-certificate-auth API Reference / extractor / ExtractorOptions

Interface: ExtractorOptions ​

Defined in: extractor.js:154

Properties ​

certificateHeader? ​

optional certificateHeader?: string

Defined in: extractor.js:158

Custom header name. Trust boundary: the proxy must strip this header from external requests; any source that can set it is trusted to assert client identity.


certificateSource? ​

optional certificateSource?: "aws-alb" | "aws-alb-verify" | "azure-app-service" | "cloudflare" | "cloudflare-rfc9440" | "envoy" | "traefik"

Defined in: extractor.js:155

Preset configuration. Trust boundary: the proxy must strip the preset's header from external requests; any source that can set it is trusted to assert client identity.


chainHeader? ​

optional chainHeader?: string

Defined in: extractor.js:161

Optional second header carrying the certificate chain alongside the leaf. Split on commas per RFC 9440, each item parsed with the same headerEncoding, results linked via issuerCertificate. Leaf and chain together may not exceed MAX_CHAIN_CERTS certificates; a longer chain header rejects the request. For non-RFC-9440 encodings the comma split may not match the encoding's list convention.


fallbackToSocket? ​

optional fallbackToSocket?: boolean

Defined in: extractor.js:167

Try socket if header extraction fails


headerEncoding? ​

optional headerEncoding?: "url-pem" | "url-pem-aws" | "xfcc" | "base64-der" | "rfc9440"

Defined in: extractor.js:166

Header encoding


includeChain? ​

optional includeChain?: boolean

Defined in: extractor.js:168

Include issuerCertificate chain


verifyHeader? ​

optional verifyHeader?: string

Defined in: extractor.js:169

Header name for upstream verification status. Pairs with verifyValue, and requires certificateSource or certificateHeader: verification applies to header-based extraction only.


verifyValue? ​

optional verifyValue?: string

Defined in: extractor.js:172

Expected value for successful verification. Pairs with verifyHeader.

Released under the MIT License.