Functional Weave
Code in Python

auth.bearer-token

The token from an HTTP Authorization header of the form "Bearer <token>" (RFC 6750), or null if it has none.

1.0.0 · published 2026-10-03 by charlie · Anterra

Pinned by 18 tests, run in TypeScript, Python and Rust.

What it does

`parseBearerToken("Bearer eyJhbGciOi...")` is `"eyJhbGciOi..."`. An API calls it with the request's `Authorization` header (or null when there is none) and answers 401 when the result is null; it never throws, because a bad header is the client's mistake and gets an answer, not a crash.

It follows RFC 6750 section 2.1: the scheme `Bearer`, one or more spaces, then a `b64token`, which is letters, digits and `- . _ ~ + /`, optionally followed by `=` padding. The scheme is case-insensitive (`bearer`, `BEARER`), as HTTP authentication schemes are (RFC 9110 section 11.1). Spaces and tabs around the whole value are ignored, since HTTP strips them from field values anyway.

For example

  • parse_bearer_token(Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl) → eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl a JWT after Bearer
  • parse_bearer_token(Bearer mF_9.B5f-4.1JqM) → mF_9.B5f-4.1JqM RFC 6750 section 2.1's example token
  • parse_bearer_token(bearer abc) → abc the scheme is case-insensitive

The function

The same function in TypeScript, Python and Rust, pinned by the same tests. Pick your language; the choice follows you around the registry.

def parse_bearer_token(authorization: Optional[str]) -> Optional[str]
authorizationstring?the Authorization header's value, or null when the request has none
returnsstring?the token, exactly as sent; null when the header is missing, another scheme or malformed

Your code names it in one line, in the file that uses it

from fune.auth.bearer_token import parse_bearer_token  # auth.bearer-token@^1
impl/python.py · 30 lines · open · raw
from typing import Optional


def _is_token_char(ch: str) -> bool:
    return ("A" <= ch <= "Z") or ("a" <= ch <= "z") or ("0" <= ch <= "9") or ch in "-._~+/"


def parse_bearer_token(authorization: Optional[str]) -> Optional[str]:
    """The token from ``Authorization: Bearer <token>`` (RFC 6750 section 2.1),
    or None. Never raises: a malformed header is an answer (401), not an error."""
    if not isinstance(authorization, str):
        return None
    value = authorization.strip(" \t")
    # Compare the scheme by ASCII case only; str.lower() would also fold
    # characters the other languages leave alone.
    scheme = value[:6]
    if len(value) < 7 or "".join(chr(ord(c) + 32) if "A" <= c <= "Z" else c for c in scheme) != "bearer" or value[6] != " ":
        return None
    i = 6
    while i < len(value) and value[i] == " ":
        i += 1
    token = value[i:]
    j = 0
    while j < len(token) and _is_token_char(token[j]):
        j += 1
    if j == 0:
        return None
    while j < len(token) and token[j] == "=":
        j += 1
    return token if j == len(token) else None

Install

fune build

With that line in your source, in a Python project (language python in fune.project), fune build resolves it and nothing else, pins them in fune.lock, downloads only the Python package of each, and builds the code above into your project’s .fune/build, one readable file per capability with a header linking back here. Or pin a range in fune.project and build in one step:

fune add auth.bearer-token
Download for Python auth.bearer-token-1.0.0-python.fune · 5,747 bytes sha256 42e38fc5d3b27ca20fcccb20b85af2051aae1c08fce6913bdeb0a3219135f23d

The manifest, vectors and README with only the Python implementation. Install it without the registry with fune add ./auth.bearer-token-1.0.0-python.fune, or fetch it from a terminal with fune pull auth.bearer-token@1.0.0:python.

The whole function, every language, is one file too: auth.bearer-token-1.0.0.fune, 8,426 bytes, sha256 087efd10d3dfaa6bd7fa838be29eaa2233f7a031d8bda534f66e615ae3a0a064. It installs into a project of any language.

Customise it in your app

The seams this capability offers. Put a marker directly above a function of your own and fune build wires it into the built code; the package on the registry is not changed, the built file’s header lists it under CUSTOMISED, and fune hooks lists every hook in the project. How hooks work.

before — your function gets the arguments and returns them, changed or not, or throws to refuse the call.

# fune: before auth.bearer-token

after — your function gets the result and the arguments, and returns the final result.

# fune: after auth.bearer-token

replace — it requires no other capability, so there is no dependency to replace.

step — your function runs at a numbered point inside the function’s body, receives the in-scope values it names as parameters, and may return replacements. List the points with fune show auth.bearer-token --steps.

# fune: step auth.bearer-token after <n|label>

Tests

A version published now needs at least 8 tests for every function, and one that expects the error for each function that throws; the registry refuses it otherwise. fune verify --all runs each case in TypeScript, Python and Rust, and a project runs them again with fune verify. This page lists the cases; it does not run them. The exact JSON is vectors.json.

CaseArgumentsExpected
a JWT after Bearer Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl → eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl
RFC 6750 section 2.1's example token Bearer mF_9.B5f-4.1JqM → mF_9.B5f-4.1JqM
the scheme is case-insensitive bearer abc → abc
upper-case scheme BEARER abc → abc
several spaces after the scheme (1*SP) Bearer abc → abc
spaces around the whole value are ignored Bearer abc → abc
trailing = padding and the + / ~ characters are allowed Bearer a+b/c~d== → a+b/c~d==
no header at all — → —
an empty header → —
the scheme with no token Bearer → —
Show the other 8 tests
CaseArgumentsExpected
the scheme and a space but no token Bearer → —
another scheme Basic dXNlcjpwYXNz → —
no space between scheme and token Bearerabc → —
a tab is not the space RFC 6750 requires after the scheme Bearer abc → —
a space inside the token Bearer abc def → —
= in the middle of the token Bearer ab=c → —
a token that is only padding Bearer == → —
a non-ASCII character in the token Bearer abcé → —

More from the author

Everything else is null: another scheme (`Basic ...`), `Bearer` with no token, a space or a tab inside the token, `=` anywhere but the end, non-ASCII characters, or `Bearerabc` with no separating space. A JWT (three base64url parts joined by dots) is always a valid `b64token`.

This only finds the token; checking it is `auth.jwt` (or `auth.access-token`, which does both).

Source: RFC 6750, The OAuth 2.0 Authorization Framework: Bearer Token Usage, section 2.1 (https://www.rfc-editor.org/rfc/rfc6750#section-2.1).

Files

PathBytes
README.md1,217
impl/python.py1,103
impl/rust.rs1,277
impl/typescript.ts1,252
vectors.json1,722