Skip to content

client-certificate-auth API Reference


client-certificate-auth API Reference / fetch / extractClientCertificateFromRequest

Function: extractClientCertificateFromRequest() ​

extractClientCertificateFromRequest(request, options?): ExtractionResult

Defined in: fetch.js:55

Extract a client certificate from a Web standard Request (or any object with an iterable headers field that yields [name, value] tuples).

Normalizes header names to lowercase and delegates to the core extractClientCertificate. Header-only: Web Request has no TLS socket, so fallbackToSocket is stripped and has no effect.

Parameters ​

request ​

A Web Request or any object whose headers iterates [name, value] pairs. Missing or non-iterable headers, and entries that are not [name, value] tuples, are ignored. A repeated certificate header is rejected where the iterable exposes it. A Web Headers joins repeated lines into one value before this sees them: url-pem, url-pem-aws, rfc9440, and base64-der under every preset but traefik reject that joined form. xfcc, and base64-der read through traefik or a hand-configured certificateHeader, use the comma grammatically and cannot tell it apart, so there the origin must be reachable only through the proxy.

headers? ​

Iterable<[string, string], any, any>

options? ​

ExtractorOptions = {}

Same options as extractClientCertificate. Header-extraction options only; socket options are ignored.

Returns ​

ExtractionResult

Examples ​

ts
// Hono
import { extractClientCertificateFromRequest } from 'client-certificate-auth/fetch';

app.get('/secure', async (c) => {
  const result = extractClientCertificateFromRequest(c.req.raw, {
    certificateSource: 'cloudflare-rfc9440',
  });
  if (!result.success) return c.text('Unauthorized', 401);
  return c.text(`Hello ${result.certificate.subject.CN}`);
});
ts
// Next.js Route Handler
export async function GET(request) {
  const result = extractClientCertificateFromRequest(request, {
    certificateSource: 'aws-alb',
  });
  if (!result.success) return new Response('Unauthorized', { status: 401 });
  return Response.json({ user: result.certificate.subject.CN });
}

Released under the MIT License.