auth.bearer-token
The token from an HTTP Authorization header of the form "Bearer <token>" (RFC 6750), or null if it has none.
1.0.0 · published 2026-10-03 by charlie · Anterra
Pinned by 18 tests, run in TypeScript, Python and Rust.
What it does
`parseBearerToken("Bearer eyJhbGciOi...")` is `"eyJhbGciOi..."`. An API calls it with the request's `Authorization` header (or null when there is none) and answers 401 when the result is null; it never throws, because a bad header is the client's mistake and gets an answer, not a crash.
It follows RFC 6750 section 2.1: the scheme `Bearer`, one or more spaces, then a `b64token`, which is letters, digits and `- . _ ~ + /`, optionally followed by `=` padding. The scheme is case-insensitive (`bearer`, `BEARER`), as HTTP authentication schemes are (RFC 9110 section 11.1). Spaces and tabs around the whole value are ignored, since HTTP strips them from field values anyway.
For example
parse_bearer_token(Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl)→ eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl a JWT after Bearerparse_bearer_token(Bearer mF_9.B5f-4.1JqM)→ mF_9.B5f-4.1JqM RFC 6750 section 2.1's example tokenparse_bearer_token(bearer abc)→ abc the scheme is case-insensitive
The function
The same function in TypeScript, Python and Rust, pinned by the same tests. Pick your language; the choice follows you around the registry.
def parse_bearer_token(authorization: Optional[str]) -> Optional[str]
| authorization | string? | the Authorization header's value, or null when the request has none |
| returns | string? | the token, exactly as sent; null when the header is missing, another scheme or malformed |
Your code names it in one line, in the file that uses it
from fune.auth.bearer_token import parse_bearer_token # auth.bearer-token@^1
from typing import Optional
def _is_token_char(ch: str) -> bool:
return ("A" <= ch <= "Z") or ("a" <= ch <= "z") or ("0" <= ch <= "9") or ch in "-._~+/"
def parse_bearer_token(authorization: Optional[str]) -> Optional[str]:
"""The token from ``Authorization: Bearer <token>`` (RFC 6750 section 2.1),
or None. Never raises: a malformed header is an answer (401), not an error."""
if not isinstance(authorization, str):
return None
value = authorization.strip(" \t")
# Compare the scheme by ASCII case only; str.lower() would also fold
# characters the other languages leave alone.
scheme = value[:6]
if len(value) < 7 or "".join(chr(ord(c) + 32) if "A" <= c <= "Z" else c for c in scheme) != "bearer" or value[6] != " ":
return None
i = 6
while i < len(value) and value[i] == " ":
i += 1
token = value[i:]
j = 0
while j < len(token) and _is_token_char(token[j]):
j += 1
if j == 0:
return None
while j < len(token) and token[j] == "=":
j += 1
return token if j == len(token) else NoneInstall
fune build
With that line in your source, in a Python project (language python in fune.project), fune build resolves it and nothing else, pins them in fune.lock, downloads only the Python package of each, and builds the code above into your project’s .fune/build, one readable file per capability with a header linking back here. Or pin a range in fune.project and build in one step:
fune add auth.bearer-token
The manifest, vectors and README with only the Python implementation. Install it without the registry with fune add ./auth.bearer-token-1.0.0-python.fune, or fetch it from a terminal with fune pull auth.bearer-token@1.0.0:python.
The whole function, every language, is one file too: auth.bearer-token-1.0.0.fune, 8,426 bytes, sha256 087efd10d3dfaa6bd7fa838be29eaa2233f7a031d8bda534f66e615ae3a0a064. It installs into a project of any language.
Customise it in your app
The seams this capability offers. Put a marker directly above a function of your own and fune build wires it into the built code; the package on the registry is not changed, the built file’s header lists it under CUSTOMISED, and fune hooks lists every hook in the project. How hooks work.
before — your function gets the arguments and returns them, changed or not, or throws to refuse the call.
# fune: before auth.bearer-token
after — your function gets the result and the arguments, and returns the final result.
# fune: after auth.bearer-token
replace — it requires no other capability, so there is no dependency to replace.
step — your function runs at a numbered point inside the function’s body, receives the in-scope values it names as parameters, and may return replacements. List the points with fune show auth.bearer-token --steps.
# fune: step auth.bearer-token after <n|label>
Tests
A version published now needs at least 8 tests for every function, and one that expects the error for each function that throws; the registry refuses it otherwise. fune verify --all runs each case in TypeScript, Python and Rust, and a project runs them again with fune verify. This page lists the cases; it does not run them. The exact JSON is vectors.json.
| Case | Arguments | Expected | |
|---|---|---|---|
| a JWT after Bearer | Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl | → | eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl |
| RFC 6750 section 2.1's example token | Bearer mF_9.B5f-4.1JqM | → | mF_9.B5f-4.1JqM |
| the scheme is case-insensitive | bearer abc | → | abc |
| upper-case scheme | BEARER abc | → | abc |
| several spaces after the scheme (1*SP) | Bearer abc | → | abc |
| spaces around the whole value are ignored | Bearer abc | → | abc |
| trailing = padding and the + / ~ characters are allowed | Bearer a+b/c~d== | → | a+b/c~d== |
| no header at all | — | → | — |
| an empty header | → | — | |
| the scheme with no token | Bearer | → | — |
Show the other 8 tests
| Case | Arguments | Expected | |
|---|---|---|---|
| the scheme and a space but no token | Bearer | → | — |
| another scheme | Basic dXNlcjpwYXNz | → | — |
| no space between scheme and token | Bearerabc | → | — |
| a tab is not the space RFC 6750 requires after the scheme | Bearer abc | → | — |
| a space inside the token | Bearer abc def | → | — |
| = in the middle of the token | Bearer ab=c | → | — |
| a token that is only padding | Bearer == | → | — |
| a non-ASCII character in the token | Bearer abcé | → | — |
More from the author
Everything else is null: another scheme (`Basic ...`), `Bearer` with no token, a space or a tab inside the token, `=` anywhere but the end, non-ASCII characters, or `Bearerabc` with no separating space. A JWT (three base64url parts joined by dots) is always a valid `b64token`.
This only finds the token; checking it is `auth.jwt` (or `auth.access-token`, which does both).
Source: RFC 6750, The OAuth 2.0 Authorization Framework: Bearer Token Usage, section 2.1 (https://www.rfc-editor.org/rfc/rfc6750#section-2.1).
Files
| Path | Bytes |
|---|---|
| README.md | 1,217 |
| impl/python.py | 1,103 |
| impl/rust.rs | 1,277 |
| impl/typescript.ts | 1,252 |
| vectors.json | 1,722 |